cbcvebase.
CVE-2025-4877
published 2025-08-20

CVE-2025-4877: There's a vulnerability in the libssh package where when a libssh consumer passes in an unexpectedly large input buffer to ssh_get_fingerprint_hash() function…

PriorityP422medium4.5CVSS 3.1
AVLACHPRLUINSUCLILAL
EPSS
0.19%
9.0th percentile
There's a vulnerability in the libssh package where when a libssh consumer passes in an unexpectedly large input buffer to ssh_get_fingerprint_hash() function. In such cases the bin_to_base64() function can experience an integer overflow leading to a memory under allocation, when that happens it's possible that the program perform out of bounds write leading to a heap corruption. This issue affects only 32-bits builds of libssh.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlibssh< libssh 0.10.6-0+deb12u2 (bookworm)libssh 0.10.6-0+deb12u2 (bookworm)
libsshlibssh>= 0 < 0.9.8-0+deb11u20.9.8-0+deb11u2
libsshlibssh>= 0 < 0.10.6-0+deb12u20.10.6-0+deb12u2
libsshlibssh>= 0 < 0.11.2-10.11.2-1
libsshlibssh>= 0 < 0.11.2-10.11.2-1
libsshlibssh>= 0 < 0.9.6-2ubuntu0.22.04.40.9.6-2ubuntu0.22.04.4
libsshlibssh>= 0 < 0.10.6-2ubuntu0.10.10.6-2ubuntu0.1
libsshlibssh>= 0 < 0.6.3-4.3ubuntu0.6+esm20.6.3-4.3ubuntu0.6+esm2
libsshlibssh>= 0 < 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm40.8.0~20170825.94fa1e38-1ubuntu0.7+esm4
libsshlibssh>= 0 < 0.9.3-2ubuntu2.5+esm10.9.3-2ubuntu2.5+esm1
msrcazl3_libssh_0.10.6-2_on_azure_linux_3.0
msrccbl2_libssh_0.10.6-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.14.5MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
osv4.5MEDIUM
vendor_debian4.5MEDIUM
vendor_msrc4.5MEDIUM
vendor_redhat4.5MEDIUM
vendor_ubuntu4.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.