A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libsshUpgrade libssh-configUpgrade libssh-devel | May 27, 2026 | May 19, 2026 |
| Alpine Linux | — | Upgrade libssh | Aug 8, 2025 | Jul 4, 2025 |
| Amazon_linux_2023 | — | Upgrade libssh-configUpgrade libssh-debugsourceUpgrade libssh-develUpgrade libsshUpgrade libssh-debuginfo | Sep 9, 2025 | Jun 24, 2025 |
| Debian | — | Upgrade libssh | Jun 26, 2025 | Jun 26, 2025 |
| Redhat_linux | — | Upgrade libssh-debugsourceNo solution existsUpgrade libssh-debuginfoUpgrade libssh-configUpgrade libsshUpgrade libssh-devel | Jul 9, 2025 | Jul 4, 2025 |
| Rocky_linux | — | Upgrade libssh-develUpgrade libsshUpgrade libssh-debugsourceUpgrade libssh-debuginfo | Jun 1, 2026 | May 28, 2026 |
| Suse | — | Upgrade libssh-develUpgrade libssh4Upgrade libssh-config | Nov 5, 2025 | Aug 14, 2025 |
| Ubuntu | — | Upgrade libssh-4 | Jul 8, 2025 | Jul 4, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 2, 2025 | Jul 4, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub