libssh Regular Expression Backtracking Vulnerability Leading to Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in libssh. A remote attacker can exploit this issue by manipulating client configuration or known_hosts files to introduce specific hostnames. When these hostnames are processed by the 'match_pattern()' function, they can cause inefficient backtracking in regular expression processing. This flaw can lead to timeouts and resource exhaustion, disrupting the client's operations.

Impact

Exploitation of this vulnerability causes resource consumption on the client side, particularly CPU usage, leading to a denial-of-service condition.

Remediation

Users are advised to avoid complex patterns in configuration files and known_hosts files.

Added: Mar 26, 2026, 9:47 PM
Updated: Mar 26, 2026, 9:47 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.6
exploitability
2.8
remediation
7.9
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.