A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libsshUpgrade libssh-develUpgrade libssh-config | May 27, 2026 | May 19, 2026 |
| Alpine Linux | — | Upgrade libssh | Aug 8, 2025 | Jul 4, 2025 |
| Amazon_linux_2023 | — | Upgrade libssh-debugsourceUpgrade libssh-configUpgrade libssh-debuginfoUpgrade libsshUpgrade libssh-devel | Sep 9, 2025 | Jun 24, 2025 |
| Debian | — | Upgrade libssh | Jun 26, 2025 | Jun 26, 2025 |
| Redhat_linux | — | Upgrade libssh-develUpgrade libssh-debuginfoUpgrade libssh-debugsourceUpgrade libssh-configUpgrade libsshNo solution exists | Jul 9, 2025 | Jul 4, 2025 |
| Rocky_linux | — | Upgrade libssh-debuginfoUpgrade libssh-debugsourceUpgrade libsshUpgrade libssh-devel | Jun 1, 2026 | May 28, 2026 |
| Suse | — | Upgrade libssh-configUpgrade libssh-develUpgrade libssh4 | Nov 5, 2025 | Aug 14, 2025 |
| Ubuntu | — | Upgrade libssh-4 | Jul 8, 2025 | Jul 4, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 2, 2025 | Jul 4, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub