PT-2025-30668 · Libssh+5 · Libssh+5

Jakub Jelen

+1

·

Published

2025-01-01

·

Updated

2026-05-19

·

CVE-2025-8114

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libssh (affected versions not specified)
Description A flaw exists in libssh, a library implementing the SSH protocol. During the key exchange (KEX) process, an allocation failure within cryptographic functions can result in a NULL pointer dereference, potentially causing the client or server to crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2026:18683
AZL-66255
AZL-66267
BDU:2025-12376
CVE-2025-8114
DLA-4385-1
JLSEC-2025-99
OESA-2025-2301
OPENSUSE-SU-2025:15545-1
OPENSUSE-SU-2026:20647-1
SUSE-SU-2025:03368-1
SUSE-SU-2025:03369-1
SUSE-SU-2025:20847-1
SUSE-SU-2025:20894-1
SUSE-SU-2025:3787-1
SUSE-SU-2025:3788-1
SUSE-SU-2025:4408-1
SUSE-SU-2025_03368-1
SUSE-SU-2025_03369-1
SUSE-SU-2026:21396-1
SUSE-SU-2026:21428-1
USN-7849-1

Affected Products

Debian
Linuxmint
Red Os
Suse
Ubuntu
Libssh