← Back

CVE-2025-5351

nvd nist
Published: Jul 4, 2025Modified: Jun 30, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD (Secondary)

Description

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.

Affected (7)

1 product
Libssh
2 products
Enterprise Linux
Openshift Container Platform
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 0.10.0 to 0.11.2
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 10.0
Version 6.0
Version 7.0
Version 8.0
Version 9.0
Version 4.0

References (3)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory

Timeline

No history available yet.