CVE-2025-4878
published 2025-07-22CVE-2025-4878: A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be…
PriorityP413low3.6CVSS 3.1
AVLACHPRLUINSUCLILAN
EPSS
0.18%
7.9th percentile
A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libssh | < libssh 0.10.6-0+deb12u2 (bookworm) | libssh 0.10.6-0+deb12u2 (bookworm) |
| libssh | libssh | >= 0 < 0.9.8-0+deb11u2 | 0.9.8-0+deb11u2 |
| libssh | libssh | >= 0 < 0.10.6-0+deb12u2 | 0.10.6-0+deb12u2 |
| libssh | libssh | >= 0 < 0.11.2-1 | 0.11.2-1 |
| libssh | libssh | >= 0 < 0.11.2-1 | 0.11.2-1 |
| libssh | libssh | >= 0 < 0.9.6-2ubuntu0.22.04.4 | 0.9.6-2ubuntu0.22.04.4 |
| libssh | libssh | >= 0 < 0.10.6-2ubuntu0.1 | 0.10.6-2ubuntu0.1 |
| libssh | libssh | >= 0 < 0.6.3-4.3ubuntu0.6+esm2 | 0.6.3-4.3ubuntu0.6+esm2 |
| libssh | libssh | >= 0 < 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4 | 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4 |
| libssh | libssh | >= 0 < 0.9.3-2ubuntu2.5+esm1 | 0.9.3-2ubuntu2.5+esm1 |
| msrc | azl3_libssh_0.10.6-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_libssh_0.10.6-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libssh_0.10.6-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libssh_0.10.6-3_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.13.6LOWCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
osv4.5MEDIUM
vendor_ubuntu4.5MEDIUM
vendor_debian3.6LOW
vendor_msrc3.6LOW
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libssh vulnerabilities
vendor_ubuntu·2025-08-14·CVSS 4.5
CVE-2025-4877 [MEDIUM] libssh vulnerabilities
Title: libssh vulnerabilities
Summary: Several security issues were fixed in libssh.
Ronald Crane discovered that libssh incorrectly handled certain base64
conversions. An attacker could use this issue to cause libssh to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2025-4877)
Ronald Crane discovered that libssh incorrectly handled the
privatekey_from_file() function. An attacker could use this issue to cause
libssh to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-4878)
Ronald Crane discovered that libssh incorrectly handled certain memory
operations in the sftp server. An attacker could possibly use this issue
to cause libssh to crash, resulting in a denial of service.
(CVE-2025-5318)
Instructions: In genera
Microsoft
Libssh: use of uninitialized variable in privatekey_from_file()
vendor_msrc·2025-07-08·CVSS 3.6
CVE-2025-4878 [LOW] CWE-416 Libssh: use of uninitialized variable in privatekey_from_file()
Libssh: use of uninitialized variable in privatekey_from_file()
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: htt
Ubuntu
libssh vulnerabilities
vendor_ubuntu·2025-07-07·CVSS 4.5
CVE-2025-5351 [MEDIUM] libssh vulnerabilities
Title: libssh vulnerabilities
Summary: Several security issues were fixed in libssh.
Ronald Crane discovered that libssh incorrectly handled certain base64
conversions. An attacker could use this issue to cause libssh to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2025-4877)
Ronald Crane discovered that libssh incorrectly handled the
privatekey_from_file() function. An attacker could use this issue to cause
libssh to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-4878)
Ronald Crane discovered that libssh incorrectly handled certain memory
operations in the sftp server. An attacker could possibly use this issue
to cause libssh to crash, resulting in a denial of service.
(CVE-2025-5318, CVE-2025-5449)
Ronald C
Red Hat
libssh: Use of uninitialized variable in privatekey_from_file()
vendor_redhat·2025-06-24·CVSS 3.6
CVE-2025-4878 [LOW] CWE-416 libssh: Use of uninitialized variable in privatekey_from_file()
libssh: Use of uninitialized variable in privatekey_from_file()
A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.
A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.
Statement: Red Hat Product Security has rated this vulnerability as having Low severity as the affected privatekey_from_file() function is deprecated and should not be u
Debian
CVE-2025-4878: libssh - A vulnerability was found in libssh, where an uninitialized variable exists unde...
vendor_debian·2025·CVSS 3.6
CVE-2025-4878 [LOW] CVE-2025-4878: libssh - A vulnerability was found in libssh, where an uninitialized variable exists unde...
A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.
Scope: local
bookworm: resolved (fixed in 0.10.6-0+deb12u2)
bullseye: resolved (fixed in 0.9.8-0+deb11u2)
forky: resolved (fixed in 0.11.2-1)
sid: resolved (fixed in 0.11.2-1)
trixie: resolved (fixed in 0.11.2-1)
OSV
libssh vulnerabilities
osv·2025-08-14·CVSS 4.5
CVE-2025-4877 [MEDIUM] libssh vulnerabilities
libssh vulnerabilities
Ronald Crane discovered that libssh incorrectly handled certain base64
conversions. An attacker could use this issue to cause libssh to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2025-4877)
Ronald Crane discovered that libssh incorrectly handled the
privatekey_from_file() function. An attacker could use this issue to cause
libssh to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-4878)
Ronald Crane discovered that libssh incorrectly handled certain memory
operations in the sftp server. An attacker could possibly use this issue
to cause libssh to crash, resulting in a denial of service.
(CVE-2025-5318)
GHSA
GHSA-q2fw-m52x-w593: A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function
ghsa_unreviewed·2025-07-22
CVE-2025-4878 [LOW] CWE-416 GHSA-q2fw-m52x-w593: A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function
A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.
OSV
CVE-2025-4878: A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function
osv·2025-07-22·CVSS 3.6
CVE-2025-4878 [LOW] CVE-2025-4878: A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function
A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.
OSV
libssh vulnerabilities
osv·2025-07-07·CVSS 4.5
CVE-2025-4877 [MEDIUM] libssh vulnerabilities
libssh vulnerabilities
Ronald Crane discovered that libssh incorrectly handled certain base64
conversions. An attacker could use this issue to cause libssh to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2025-4877)
Ronald Crane discovered that libssh incorrectly handled the
privatekey_from_file() function. An attacker could use this issue to cause
libssh to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-4878)
Ronald Crane discovered that libssh incorrectly handled certain memory
operations in the sftp server. An attacker could possibly use this issue
to cause libssh to crash, resulting in a denial of service.
(CVE-2025-5318, CVE-2025-5449)
Ronald Crane discovered that libssh incorrectly handled exporting keys.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-4878 mingw-libssh2: Use of uninitialized variable in privatekey_from_file() [fedora-42]
bugzilla·2025-07-22·CVSS 3.6
CVE-2025-4878 [LOW] CVE-2025-4878 mingw-libssh2: Use of uninitialized variable in privatekey_from_file() [fedora-42]
CVE-2025-4878 mingw-libssh2: Use of uninitialized variable in privatekey_from_file() [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close
Bugzilla
CVE-2025-4878 libssh: Use of uninitialized variable in privatekey_from_file()
bugzilla·2025-07-03·CVSS 3.6
CVE-2025-4878 [LOW] CVE-2025-4878 libssh: Use of uninitialized variable in privatekey_from_file()
CVE-2025-4878 libssh: Use of uninitialized variable in privatekey_from_file()
The privatekey_from_file() uses an uninitialized variable under certain conditions, such as if the file specified by the filename argument doesn't exist. This causes the code to return an invalid private key. This defect, in turn, might cause signing failure. The bug might also cause a Use-After-Free or corrupt the heap. Note that privatekey_from_file() is a deprecated function and shouldn't be used anymore!
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:18683 https://access.redhat.com/errata/RHSA-2026:18683
https://access.redhat.com/errata/RHSA-2026:18683https://access.redhat.com/security/cve/CVE-2025-4878https://bugzilla.redhat.com/show_bug.cgi?id=2376184https://git.libssh.org/projects/libssh.git/commit/?id=697650caa97eaf7623924c75f9fcfec6dd423cd1https://git.libssh.org/projects/libssh.git/commit/?id=b35ee876adc92a208d47194772e99f9c71e0bedbhttps://www.libssh.org/security/advisories/CVE-2025-4878.txt
2025-07-22
Published