8.8
CVE-2025-5372
- EPSS 0.43%
- Veröffentlicht 04.07.2025 06:01:27
- Zuletzt bearbeitet 01.09.2026 12:17:26
- Erkennungen
Libssh: incorrect return code handling in ssh_kdf() in libssh
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Openshift Container Platform Version 4.0
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.357 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| RedHat | 5 | 1.6 | 3.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
|
CWE-682 Incorrect Calculation
The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://bugzilla.redhat.com/show_bug.cgi?id=2369388
https://access.redhat.com/errata/RHSA-2025:21977
https://access.redhat.com/errata/RHSA-2025:23024
https://access.redhat.com/errata/RHSA-2026:20610
https://access.redhat.com/errata/RHSA-2026:24349
https://access.redhat.com/errata/RHSA-2026:25911
https://access.redhat.com/security/cve/CVE-2025-5372