Home

Description

A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.

PUBLISHED Reserved 2025-05-29 | Published 2025-06-24 | Updated 2026-03-18 | Assigner redhat




HIGH: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Problem types

Out-of-bounds Read

Product status

Default status
unaffected

Any version before 0.11.2
affected

Default status
affected

0:0.11.1-4.el10_0 (rpm) before *
unaffected

Default status
affected

0:0.11.1-4.el10_1 (rpm) before *
unaffected

Default status
affected

0:0.9.6-15.el8_10 (rpm) before *
unaffected

Default status
affected

0:0.9.6-15.el8_10 (rpm) before *
unaffected

Default status
affected

0:0.9.0-4.el8_2.1 (rpm) before *
unaffected

Default status
affected

0:0.9.4-2.el8_4.1 (rpm) before *
unaffected

Default status
affected

0:0.9.4-2.el8_4.1 (rpm) before *
unaffected

Default status
affected

0:0.9.6-4.el8_6.1 (rpm) before *
unaffected

Default status
affected

0:0.9.6-4.el8_6.1 (rpm) before *
unaffected

Default status
affected

0:0.9.6-4.el8_6.1 (rpm) before *
unaffected

Default status
affected

0:0.9.6-13.el8_8.1 (rpm) before *
unaffected

Default status
affected

0:0.9.6-13.el8_8.1 (rpm) before *
unaffected

Default status
affected

0:0.10.4-15.el9_6 (rpm) before *
unaffected

Default status
affected

0:0.10.4-15.el9_7 (rpm) before *
unaffected

Default status
affected

0:0.10.4-15.el9_6 (rpm) before *
unaffected

Default status
affected

0:0.10.4-15.el9_7 (rpm) before *
unaffected

Default status
affected

0:0.9.6-3.el9_0.1 (rpm) before *
unaffected

Default status
affected

0:0.10.4-9.el9_2.1 (rpm) before *
unaffected

Default status
affected

0:0.10.4-13.el9_4.1 (rpm) before *
unaffected

Default status
affected

412.86.202511191939-0 (rpm) before *
unaffected

Default status
affected

413.92.202511261311-0 (rpm) before *
unaffected

Default status
affected

414.92.202511122212-0 (rpm) before *
unaffected

Default status
affected

415.92.202601271320-0 (rpm) before *
unaffected

Default status
affected

416.94.202601071926-0 (rpm) before *
unaffected

Default status
affected

417.94.202510282022-0 (rpm) before *
unaffected

Default status
affected

418.94.202511041748-0 (rpm) before *
unaffected

Default status
affected

4.19.9.6.202510281054-0 (rpm) before *
unaffected

Default status
affected

4.20.9.6.202510290321-0 (rpm) before *
unaffected

Default status
affected

sha256:bddcf7ab6d576572b6d60822c313ffebcd9869e4fde93e32ac327821f93cf32b (rpm) before *
unaffected

Default status
affected

sha256:7856bdb7ae0d643a7b9362c164d4d4fe3c0c7186f5fff73a7ae9835b3df52e57 (rpm) before *
unaffected

Default status
affected

sha256:dce6b0ea03379bf06664a5200af8b5f5ae3fad13cdce6d21873843f22554800b (rpm) before *
unaffected

Default status
affected

sha256:fa844e16d06e871f1a5dbc2fd5b3882d28112eee8d6bee601d94c96295c5e24f (rpm) before *
unaffected

Default status
affected

sha256:53007894763e03f609c35c727cb738db3c2130b19fa0e1069c24240e0870fb7a (rpm) before *
unaffected

Default status
affected

sha256:b5ee1febe929df3dd67df124aeb65d1920af553e667c2929a6865784ce546dc3 (rpm) before *
unaffected

Default status
affected

sha256:f242d27114fa7546df4d7261cccbd8586e9e6ba2487f02e260d8880807b94f43 (rpm) before *
unaffected

Default status
affected

sha256:dcbae88d4be5b004ff7473bcfbbd57946c773f7e77fc99da0b5b023310f55ddd (rpm) before *
unaffected

Default status
affected

sha256:8ad291327a8410feb2d34afeb0d0c7f847a1cffc838883b65d71427b3f97670a (rpm) before *
unaffected

Default status
affected

sha256:0fbed65da8c168be024b4ec28e9c5a860ce81c5bee69ebea24002407dc002be8 (rpm) before *
unaffected

Default status
affected

sha256:83583f8010629b65533926a11163565efd4d8b32433fe279218b60cdb13da13f (rpm) before *
unaffected

Timeline

2025-05-29:Reported to Red Hat.
2025-06-24:Made public.

Credits

Red Hat would like to thank Ronald Crane for reporting this issue.

References

access.redhat.com/errata/RHSA-2025:18231 (RHSA-2025:18231) vendor-advisory

access.redhat.com/errata/RHSA-2025:18275 (RHSA-2025:18275) vendor-advisory

access.redhat.com/errata/RHSA-2025:18286 (RHSA-2025:18286) vendor-advisory

access.redhat.com/errata/RHSA-2025:19012 (RHSA-2025:19012) vendor-advisory

access.redhat.com/errata/RHSA-2025:19098 (RHSA-2025:19098) vendor-advisory

access.redhat.com/errata/RHSA-2025:19101 (RHSA-2025:19101) vendor-advisory

access.redhat.com/errata/RHSA-2025:19295 (RHSA-2025:19295) vendor-advisory

access.redhat.com/errata/RHSA-2025:19300 (RHSA-2025:19300) vendor-advisory

access.redhat.com/errata/RHSA-2025:19313 (RHSA-2025:19313) vendor-advisory

access.redhat.com/errata/RHSA-2025:19400 (RHSA-2025:19400) vendor-advisory

access.redhat.com/errata/RHSA-2025:19401 (RHSA-2025:19401) vendor-advisory

access.redhat.com/errata/RHSA-2025:19470 (RHSA-2025:19470) vendor-advisory

access.redhat.com/errata/RHSA-2025:19472 (RHSA-2025:19472) vendor-advisory

access.redhat.com/errata/RHSA-2025:19807 (RHSA-2025:19807) vendor-advisory

access.redhat.com/errata/RHSA-2025:19864 (RHSA-2025:19864) vendor-advisory

access.redhat.com/errata/RHSA-2025:20943 (RHSA-2025:20943) vendor-advisory

access.redhat.com/errata/RHSA-2025:21013 (RHSA-2025:21013) vendor-advisory

access.redhat.com/errata/RHSA-2025:21329 (RHSA-2025:21329) vendor-advisory

access.redhat.com/errata/RHSA-2025:21829 (RHSA-2025:21829) vendor-advisory

access.redhat.com/errata/RHSA-2025:22275 (RHSA-2025:22275) vendor-advisory

access.redhat.com/errata/RHSA-2025:23078 (RHSA-2025:23078) vendor-advisory

access.redhat.com/errata/RHSA-2025:23079 (RHSA-2025:23079) vendor-advisory

access.redhat.com/errata/RHSA-2025:23080 (RHSA-2025:23080) vendor-advisory

access.redhat.com/errata/RHSA-2026:0326 (RHSA-2026:0326) vendor-advisory

access.redhat.com/errata/RHSA-2026:1541 (RHSA-2026:1541) vendor-advisory

access.redhat.com/errata/RHSA-2026:3461 (RHSA-2026:3461) vendor-advisory

access.redhat.com/errata/RHSA-2026:3462 (RHSA-2026:3462) vendor-advisory

access.redhat.com/security/cve/CVE-2025-5318 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2369131 (RHBZ#2369131) issue-tracking

www.libssh.org/security/advisories/CVE-2025-5318.txt

cve.org (CVE-2025-5318)

nvd.nist.gov (CVE-2025-5318)

Download JSON