CVE-2025-5372
published 2025-07-04CVE-2025-5372: A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to…
PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.41%
33.0th percentile
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libssh | < libssh 0.10.6-0+deb12u2 (bookworm) | libssh 0.10.6-0+deb12u2 (bookworm) |
| libssh | libssh | < 0.11.2 | 0.11.2 |
| libssh | libssh | >= 0 < 0.9.8-0+deb11u2 | 0.9.8-0+deb11u2 |
| libssh | libssh | >= 0 < 0.10.6-0+deb12u2 | 0.10.6-0+deb12u2 |
| libssh | libssh | >= 0 < 0.11.2-1 | 0.11.2-1 |
| libssh | libssh | >= 0 < 0.11.2-1 | 0.11.2-1 |
| libssh | libssh | >= 0 < 0.9.6-2ubuntu0.22.04.4 | 0.9.6-2ubuntu0.22.04.4 |
| libssh | libssh | >= 0 < 0.10.6-2ubuntu0.1 | 0.10.6-2ubuntu0.1 |
| msrc | azl3_libssh_0.10.6-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_libssh_0.10.6-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libssh_0.10.6-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libssh_0.10.6-2_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian5.0MEDIUM
vendor_msrc5.0MEDIUM
vendor_oracle5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu4.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Containers and Related Services (libssh) — CVE-2025-5372
vendor_oracle·2026-01-15·CVSS 5.0
CVE-2025-5372 [MEDIUM] Oracle Oracle Siebel CRM Risk Matrix: Containers and Related Services (libssh) — CVE-2025-5372
Oracle Oracle Siebel CRM Risk Matrix: Containers and Related Services (libssh) vulnerability
CVE: CVE-2025-5372
CVSS: 5.0
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Microsoft
Libssh: incorrect return code handling in ssh_kdf() in libssh
vendor_msrc·2025-07-08·CVSS 5.0
CVE-2025-5372 [MEDIUM] CWE-682 Libssh: incorrect return code handling in ssh_kdf() in libssh
Libssh: incorrect return code handling in ssh_kdf() in libssh
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https
Ubuntu
libssh vulnerabilities
vendor_ubuntu·2025-07-07·CVSS 4.5
CVE-2025-5351 [MEDIUM] libssh vulnerabilities
Title: libssh vulnerabilities
Summary: Several security issues were fixed in libssh.
Ronald Crane discovered that libssh incorrectly handled certain base64
conversions. An attacker could use this issue to cause libssh to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2025-4877)
Ronald Crane discovered that libssh incorrectly handled the
privatekey_from_file() function. An attacker could use this issue to cause
libssh to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-4878)
Ronald Crane discovered that libssh incorrectly handled certain memory
operations in the sftp server. An attacker could possibly use this issue
to cause libssh to crash, resulting in a denial of service.
(CVE-2025-5318, CVE-2025-5449)
Ronald C
Red Hat
libssh: Incorrect Return Code Handling in ssh_kdf() in libssh
vendor_redhat·2025-06-24·CVSS 5.0
CVE-2025-5372 [MEDIUM] CWE-682 libssh: Incorrect Return Code Handling in ssh_kdf() in libssh
libssh: Incorrect Return Code Handling in ssh_kdf() in libssh
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return v
Debian
CVE-2025-5372: libssh - A flaw was found in libssh versions built with OpenSSL versions older than 3.0, ...
vendor_debian·2025·CVSS 5.0
CVE-2025-5372 [MEDIUM] CVE-2025-5372: libssh - A flaw was found in libssh versions built with OpenSSL versions older than 3.0, ...
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.
Scope: local
bookworm: resolved (fixed in 0.10.6-0+deb12u2)
bullseye: resolved (fixed in 0.9.8-0+deb11u2)
forky: resolved (fixed in 0.11.2-1)
sid: resolved (fixed in 0.11.2-1)
trixie: resolved (fixed in 0.11.2-1)
OSV
libssh vulnerabilities
osv·2025-07-07·CVSS 4.5
CVE-2025-4877 [MEDIUM] libssh vulnerabilities
libssh vulnerabilities
Ronald Crane discovered that libssh incorrectly handled certain base64
conversions. An attacker could use this issue to cause libssh to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2025-4877)
Ronald Crane discovered that libssh incorrectly handled the
privatekey_from_file() function. An attacker could use this issue to cause
libssh to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-4878)
Ronald Crane discovered that libssh incorrectly handled certain memory
operations in the sftp server. An attacker could possibly use this issue
to cause libssh to crash, resulting in a denial of service.
(CVE-2025-5318, CVE-2025-5449)
Ronald Crane discovered that libssh incorrectly handled exporting keys.
GHSA
GHSA-59w5-j22f-h3rv: A flaw was found in libssh versions built with OpenSSL versions older than 3
ghsa_unreviewed·2025-07-04
CVE-2025-5372 [MEDIUM] CWE-682 GHSA-59w5-j22f-h3rv: A flaw was found in libssh versions built with OpenSSL versions older than 3
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.
OSV
CVE-2025-5372: A flaw was found in libssh versions built with OpenSSL versions older than 3
osv·2025-07-04·CVSS 8.8
CVE-2025-5372 [HIGH] CVE-2025-5372: A flaw was found in libssh versions built with OpenSSL versions older than 3
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-5372 libssh2: Incorrect Return Code Handling in ssh_kdf() in libssh [epel-all]
bugzilla·2026-04-06·CVSS 5.0
CVE-2025-5372 [MEDIUM] CVE-2025-5372 libssh2: Incorrect Return Code Handling in ssh_kdf() in libssh [epel-all]
CVE-2025-5372 libssh2: Incorrect Return Code Handling in ssh_kdf() in libssh [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
There is no function ssh_kdf() in libssh2, which is a different codebase than libssh, not a derivative of it.
Bugzilla
CVE-2025-5372 mingw-libssh2: Incorrect Return Code Handling in ssh_kdf() in libssh [fedora-all]
bugzilla·2025-07-04·CVSS 8.8
CVE-2025-5372 [HIGH] CVE-2025-5372 mingw-libssh2: Incorrect Return Code Handling in ssh_kdf() in libssh [fedora-all]
CVE-2025-5372 mingw-libssh2: Incorrect Return Code Handling in ssh_kdf() in libssh [fedora-all]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2369388
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of
Bugzilla
CVE-2025-5372 libssh: Incorrect Return Code Handling in ssh_kdf() in libssh
bugzilla·2025-05-30·CVSS 5.0
CVE-2025-5372 [MEDIUM] CVE-2025-5372 libssh: Incorrect Return Code Handling in ssh_kdf() in libssh
CVE-2025-5372 libssh: Incorrect Return Code Handling in ssh_kdf() in libssh
Incorrect Success Return vulnerability in the ssh_kdf() function of libssh when built with OpenSSL versions prior to 3.0. This issue arises because libssh interprets OpenSSL's return value 0 (indicating failure) as SSH_OK (indicating success). As a result, on failure, the function may return success without initializing the output key buffers. This can lead to the use of uninitialized cryptographic keys, affecting the encryption and decryption of SSH traffic. The vulnerability allows an attacker to exploit improper key handling, potentially resulting in data leakage, integrity issues, or denial of service during SSH communication.
Discussion:
This issue has been addressed in the following products:
Red Hat Ente
https://access.redhat.com/errata/RHSA-2025:21977https://access.redhat.com/errata/RHSA-2025:23024https://access.redhat.com/errata/RHSA-2026:20610https://access.redhat.com/errata/RHSA-2026:24349https://access.redhat.com/errata/RHSA-2026:25911https://access.redhat.com/security/cve/CVE-2025-5372https://bugzilla.redhat.com/show_bug.cgi?id=2369388
2025-07-04
Published