libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libssh | Aug 30, 2017 | Apr 13, 2016 |
| Debian | — | Upgrade libssh | Feb 23, 2016 | Feb 23, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 27, 2016 |
| Freebsd | — | Upgrade libssh | Dec 10, 2025 | Mar 5, 2016 |
| Gentoo Linux | — | Upgrade net-libs/libssh.Upgrade net-libs/libssh2. | Oct 30, 2017 | Apr 13, 2016 |
| Suse | — | Upgrade libssh-develUpgrade libssh2Upgrade libssh-devel-docUpgrade libssh4Upgrade libssh4-32bit | Mar 1, 2016 | Mar 1, 2016 |
| Ubuntu | — | Upgrade libssh-4 | Feb 23, 2016 | Feb 23, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub