PT-2025-36723 · Libssh+5 · Libssh+5

Francesco Rollo

·

Published

2025-01-01

·

Updated

2026-05-19

·

CVE-2025-8277

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: libssh (affected versions not specified)
Description: A memory exhaustion issue exists in libssh’s handling of key exchange (KEX) processes. When a client repeatedly sends incorrect KEX guesses, the library fails to free memory during rekey operations, potentially leading to system memory exhaustion and client-side crashes, particularly when using libgcrypt.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Leak

Weakness Enumeration

Related Identifiers

ALSA-2026:18683
AZL-67092
AZL-67095
BDU:2025-13879
CVE-2025-8277
DLA-4385-1
OESA-2025-2342
OPENSUSE-SU-2025:15545-1
SUSE-SU-2025:03368-1
SUSE-SU-2025:03369-1
SUSE-SU-2025:20847-1
SUSE-SU-2025:20894-1
SUSE-SU-2025:3787-1
SUSE-SU-2025:3788-1
SUSE-SU-2025:3897-1
SUSE-SU-2025_03368-1
SUSE-SU-2025_03369-1
SUSE-SU-2025_3897-1
USN-8051-1
USN-8051-2

Affected Products

Debian
Linuxmint
Red Os
Suse
Ubuntu
Libssh