« List of all CVEs

CVE-2025-5372

Libssh: incorrect return code handling in ssh_kdf() in libssh

Published: 7/4/2025 Last updated: 7/12/2026 Reserved: 5/30/2025

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5 Medium CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Opam packages affected (1)

libssh

Products affected (26)

Product Vendor Version
Red Hat Enterprise Linux 8 Red Hat AQUOS SH-M02 build number 01.00.05 and earlier, AQUOS SH-RM02 build number 01.00.04 and earlier, AQUOS mini SH-M03 build number 01.00.04 and earlier, AQUOS Keitai SH-N01 build number 01.00.01 and earlier, AQUOS L2 (UQ mobile/J:COM) build number 01.00.05 and earlier, AQUOS sense lite SH-M05 build number 03.00.04 and earlier, AQUOS sense (UQ mobile) build number 03.00.03 and earlier, AQUOS compact SH-M06 build number 02.00.02 and earlier, AQUOS sense plus SH-M07 build number 02.00.02 and earlier, AQUOS sense2 SH-M08 build number 02.00.05 and earlier, and AQUOS sense2 (UQ mobile) build number 02.00.06 and earlier
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat < 6.1.41.0
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Red Hat 11.3
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier versions
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Red Hat Android kernel
Red Hat Enterprise Linux 8.8 Telecommunications Update Service Red Hat < publication
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat < publication
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Red Hat n/a
Red Hat Enterprise Linux 10 Red Hat n/a
Red Hat Enterprise Linux 8.8 Telecommunications Update Service Red Hat <= 1.0.0
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat < 7.11
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Red Hat < 7.40
Red Hat Enterprise Linux 10 Red Hat Prior to 10.7.0
Red Hat Enterprise Linux 9 Red Hat < unspecified
Red Hat Enterprise Linux 9 Red Hat V600R006C10,V600R006C10SPC100
Red Hat Enterprise Linux 8 Red Hat < 78.10
Red Hat Enterprise Linux 8 Red Hat < 1.26.0
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat < 15.1R7-S10
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Red Hat < 19.2R1-S7, 19.2R3-S3
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat < 20.4R2-S1, 20.4R3
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Red Hat unspecified
Red Hat Enterprise Linux 6 Red Hat Foxit Reader 10.1.3.37598
Red Hat Enterprise Linux 7 Red Hat V2.0
Red Hat Enterprise Linux 7 Red Hat n/a
Red Hat Enterprise Linux 6 Red Hat < 1.7.1
Red Hat OpenShift Container Platform 4 Red Hat < 8.5.5

References (14)