« List of all CVEs

CVE-2025-5318

Libssh: out-of-bounds read in sftp_handle()

Published: 6/24/2025 Last updated: 3/18/2026 Reserved: 5/29/2025

A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 8.1 High CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Opam packages affected (1)

libssh

Products affected (32)

Product Vendor Version
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Red Hat < 10.0.26100.2894
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat < 10.0.19044.5737
Red Hat Enterprise Linux 8.8 Telecommunications Update Service Red Hat < 10.0.19044.6216
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Red Hat < 10.0.17763.6775
Red Hat Enterprise Linux 8.8 Telecommunications Update Service Red Hat < 10.0.26100.2894
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat < 10.0.22631.5768
Red Hat Enterprise Linux 9 Red Hat < 10.0.17763.7136
Red Hat Enterprise Linux 9 Red Hat < https://aka.ms/OfficeSecurityReleases
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Red Hat < 6.2.9200.25273
Red Hat Enterprise Linux 9.4 Extended Update Support Red Hat < 10.0.17763.7558
Red Hat Enterprise Linux 10 Red Hat < 10.0.26100.2894
Red Hat Enterprise Linux 8 Red Hat < 10.0.14393.8246
Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat < 10.0.22631.5189
< 6.3.9600.22523
Red Hat Enterprise Linux 10 Red Hat < 10.0.26100.2894
Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat < 10.0.22621.5189
Red Hat Enterprise Linux 8.6 Telecommunications Update Service Red Hat < 10.0.26100.2894
Red Hat AI Inference Server 3.2 Red Hat < 10.0.19045.6216
Red Hat AI Inference Server 3.2 Red Hat < 10.0.14393.7969
Red Hat AI Inference Server 3.2 Red Hat < 10.0.22631.5768
Red Hat AI Inference Server 3.2 Red Hat < 10.0.19044.5371
Red Hat AI Inference Server 3.2 Red Hat < 6.2.9200.25273
Red Hat OpenShift Container Platform 4.13 Red Hat < 10.0.26100.2894
Red Hat OpenShift Container Platform 4.12 Red Hat < 10.0.22631.5189
Red Hat OpenShift Container Platform 4.19 Red Hat < 10.0.26100.2894
Red Hat OpenShift Container Platform 4.20 Red Hat < 8.0.12
Red Hat OpenShift Container Platform 4.14 Red Hat < 10.0.22631.5189
Red Hat OpenShift distributed tracing 3.7.1 Red Hat < 10.0.17763.7558
Red Hat OpenShift distributed tracing 3.7.1 Red Hat < 10.0.22631.5189
Red Hat OpenShift distributed tracing 3.7.1 Red Hat < 10.0.26100.3775
Red Hat OpenShift distributed tracing 3.7.1 Red Hat < 9.0.1
Red Hat OpenShift distributed tracing 3.7.1 Red Hat < 10.0.19045.5737

References (60)

Credits (2)