Looks like this one has patches available, but they may not be pushed out to all distros.
libssh2 is used by curl but NOT OpenSSH as far as I can tell.
It’s an out-of-bounds write vulnerability that allows clients to write past the end of the buffer and corrupt memory. No authentication is required. If they corrupt heap memory in the right way, it may lead to remote code execution.
I haven’t seen any chatter about anyone exploiting it yet, anyone else?