Description
A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.
Problem types
Product status
Any version before 0.11.3
Timeline
| 2025-07-24: | Reported to Red Hat. |
| 2025-07-24: | Made public. |
Credits
Red Hat would like to thank Jakub Jelen and Philippe Antoine for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-8114
bugzilla.redhat.com/show_bug.cgi?id=2383220 (RHBZ#2383220)
git.libssh.org/...d=53ac23ded4cb2c5463f6c4cd1525331bd578812d
git.libssh.org/projects/libssh.git/commit/?id=65f363c9
www.libssh.org/security/advisories/CVE-2025-8114.txt