The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libssh2 | Aug 30, 2017 | Apr 13, 2016 |
| Centos_linux | — | Upgrade libssh2-docsUpgrade libssh2Upgrade libssh2-devel | Jul 6, 2016 | Mar 10, 2016 |
| Debian | — | Upgrade libssh2 | Mar 11, 2016 | Feb 23, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Aug 11, 2016 |
| Gentoo Linux | — | Upgrade net-libs/libssh2.Upgrade net-libs/libssh. | Oct 30, 2017 | Apr 13, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade libssh2 | Nov 30, 2017 | Apr 13, 2016 |
| Oracle Solaris | — | Upgrade library/libssh2 to version 1.7.0-0.175.3.14.0.4.0 on Solaris 11.3 | May 29, 2017 | Apr 13, 2016 |
| Oracle_linux | — | Upgrade libssh2-docsUpgrade libssh2-develUpgrade libssh2 | Apr 13, 2016 | Apr 13, 2016 |
| Suse | — | Upgrade libssh2-develUpgrade libssh2-1-32bitUpgrade sles12sp1-docker-imageUpgrade libssh2-1-x86Upgrade libssh2-1Upgrade sles12-docker-image | Apr 13, 2016 | Apr 13, 2016 |
| Ubuntu | — | Upgrade libssh2 | Nov 19, 2024 | Apr 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub