PT-2026-50786 · Libssh2 · Libssh2

Joshua Rogers

+1

·

Published

2026-06-18

·

Updated

2026-06-18

·

CVE-2025-15661

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH FXP NAME response. Attackers can supply a link len value larger than the actual packet data in SSH FXP NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15661

Affected Products

Libssh2