A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-libsshalma-upgrade-libssh-configalma-upgrade-libssh-devel | May 27, 2026 | May 19, 2026 | |
| Alpine Linux | alpine-linux-upgrade-libssh | Aug 8, 2025 | Jul 4, 2025 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-libsshamazon-linux-2023-upgrade-libssh-configamazon-linux-2023-upgrade-libssh-debuginfoamazon-linux-2023-upgrade-libssh-debugsourceamazon-linux-2023-upgrade-libssh-devel | Sep 9, 2025 | Jun 24, 2025 | |
| Debian | debian-upgrade-libssh | Jun 26, 2025 | Jun 26, 2025 | |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-libsshredhat-upgrade-libssh-configredhat-upgrade-libssh-debuginforedhat-upgrade-libssh-debugsourceredhat-upgrade-libssh-devel | Jul 9, 2025 | Jul 4, 2025 | |
| Rocky_linux | rocky-upgrade-libsshrocky-upgrade-libssh-debuginforocky-upgrade-libssh-debugsourcerocky-upgrade-libssh-devel | Jun 1, 2026 | May 28, 2026 | |
| Suse | — | suse-upgrade-libssh-configsuse-upgrade-libssh-develsuse-upgrade-libssh4 | Nov 5, 2025 | Aug 14, 2025 |
| Ubuntu | ubuntu-upgrade-libssh-4 | Jul 8, 2025 | Jul 4, 2025 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Sep 2, 2025 | Jul 4, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub