Hi Gyorgy Sarvari,
 
This CVE is fixed in libssh-0.12.0 tag and master branch which is major upgrade for master branch. Please refer below URL:
projects/libssh.git - libssh shared repository
 
Please suggest if we can upgrade to libssh-0.12.0 release or not.
 
Regards,
Deepak