Debian administrators received two security advisories addressing critical flaws in the kissfft and libssh packages. The kissfft library contains two integer overflow bugs tracked under CVE-2025-34297 and CVE-2026-41445 that now require version 131.1.0-1+deb11u1 on Debian 11 bullseye. The libssh C library faces fourteen separate vulnerabilities across multiple CVEs, including risks for denial of service and arbitrary code execution, with a patch available at version 0.11.5-0+deb13u1 for the trixie distribution.
[SECURITY] [DLA 4715-1] kissfft security update
[SECURITY] [DSA 6410-1] libssh security update
[SECURITY] [DLA 4715-1] kissfft security update
[SECURITY] [DSA 6410-1] libssh security update
[SECURITY] [DLA 4715-1] kissfft security update
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4715-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Thorsten Alteholz
August 02, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : kissfft
Version : 131.1.0-1+deb11u1
CVE ID : CVE-2025-34297 CVE-2026-41445
Two issues have been found in kissfft, a mixed-radix Fast Fourier
Transform library. The issues are related to integer overflows.
For Debian 11 bullseye, these problems have been fixed in version
131.1.0-1+deb11u1.
We recommend that you upgrade your kissfft packages.
For the detailed security status of kissfft please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/kissfft
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
[SECURITY] [DSA 6410-1] libssh security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6410-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 02, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : libssh
CVE ID : CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967
CVE-2026-0968 CVE-2026-3731 CVE-2026-15370 CVE-2026-59843
CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847
CVE-2026-59848 CVE-2026-59849 CVE-2026-59850
Debian Bug : 1127693 1142537
Several vulnerabilities were discovered in libssh, a tiny C SSH library,
which may result in denial of service, information disclosure and
potentially the execution of arbitrary code.
For the stable distribution (trixie), these problems have been fixed in
version 0.11.5-0+deb13u1.
We recommend that you upgrade your libssh packages.
For the detailed security status of libssh please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/libssh
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/