An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
- CVSS 3.0 Base Score: 5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libssh2 | Mar 22, 2019 | Mar 20, 2019 |
| Amazon Linux Ami 2 | — | Upgrade libssh2-docsUpgrade libssh2Upgrade libssh2-develUpgrade libssh2-debuginfo | May 17, 2023 | Mar 21, 2019 |
| Amazon_linux | — | Upgrade libssh2 | Jun 7, 2023 | Mar 20, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 20, 2019 |
| Debian | — | Upgrade libssh2 | Mar 27, 2019 | Mar 21, 2019 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 14, 2025 |
| Freebsd | — | Upgrade linux-c6-libssh2Upgrade linux-c7-libssh2Upgrade libssh2 | Jul 8, 2019 | Apr 18, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libssh2 | May 1, 2019 | Mar 21, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libssh2 | May 1, 2019 | Mar 21, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libssh2 | May 1, 2019 | Mar 21, 2019 |
| Oracle Solaris | — | Upgrade library/libssh2 to version 1.8.2-11.4.11.0.1.1.0 on Solaris 11.4 | Jul 17, 2019 | Mar 21, 2019 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 21, 2019 |
| Suse | — | Upgrade libssh2-1Upgrade libssh2-develUpgrade libssh2-1-32bitUpgrade libssh2-1-x86 | Mar 20, 2019 | Mar 20, 2019 |
| Ubuntu | — | Upgrade libssh2-1 (Ubuntu Pro) | Mar 22, 2023 | Mar 21, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 20, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub