A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
Credits
Red Hat would like to thank Haruto Kimura, Rinku Das, and Yi Lin for reporting this issue.