← Back

CVE-2025-5318

nvd nist
Published: Jun 24, 2025Modified: Jul 21, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Exploitability: 2.8 / Impact: 5.2
Source: NVD (Secondary)

Description

A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.

Affected (5)

2 products
Enterprise Linux
Openshift Container Platform
1 product
Libssh
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 10.0
Version 8.0
Version 9.0
Version 4.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.11.2

References (30)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Vendor Advisory

Timeline

No history available yet.