libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.
CVSS Details
- CVSS 4.0 Base Score: 8.3 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libssh2-develUpgrade libssh2-docsUpgrade libssh2Upgrade libssh2-debuginfo | Jul 22, 2026 | Jul 22, 2026 |
| Amazon_linux_2023 | — | Upgrade libssh2-debuginfoUpgrade libssh2-develUpgrade libssh2-debugsourceUpgrade libssh2Upgrade libssh2-docs | Jul 21, 2026 | Jun 28, 2026 |
| Debian | — | Upgrade libssh2 | Sep 21, 2026 | Jun 28, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 28, 2026 |
| Ubuntu | — | Upgrade libssh2-1t64 | Jul 13, 2026 | Jun 28, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub