Hi Chris,
I guess this is for libssh2 for AIX from AIX toolbox?
Can you please use open source development forum for better visibility.
https://community.ibm.com/community/user/groups/community-home/digestviewer?CommunityKey=329e8662-cb5a-4e9e-80ee-47b1c3b5848c
Regarding fix for the CVE, community has not released a newer version of libssh2 with fix.