SUMMARY Under Gentoo Linux + LibreSSL the following package dependency causes an upgrade path problem: kde-apps/kio-extras-18.08.3-r1 (sftp ? net-libs/libssh[sftp]) due to this statement: https://bugs.libssh.org/T128 This means for a non-dev KDE user either to switch away from LibreSSL or to live with the older vulnerable version 0.7.4 (which compiles with LibreSSL-2.6.5).
We are at the mercy of libssh here.