CVE-2025-5987
published 2025-07-07CVE-2025-5987: A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not…
PriorityP350high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.44%
70.2th percentile
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libssh | < libssh 0.10.6-0+deb12u2 (bookworm) | libssh 0.10.6-0+deb12u2 (bookworm) |
| libssh | libssh | >= 0 < 0.10.6-0+deb12u2 | 0.10.6-0+deb12u2 |
| libssh | libssh | >= 0 < 0.11.2-1 | 0.11.2-1 |
| libssh | libssh | >= 0 < 0.11.2-1 | 0.11.2-1 |
| libssh | libssh | >= 0 < 0.9.6-2ubuntu0.22.04.4 | 0.9.6-2ubuntu0.22.04.4 |
| libssh | libssh | >= 0 < 0.10.6-2ubuntu0.1 | 0.10.6-2ubuntu0.1 |
| libssh | libssh | >= 0.10.0 < 0.11.2 | 0.11.2 |
| msrc | azl3_libssh_0.10.6-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_libssh_0.10.6-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libssh_0.10.6-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libssh_0.10.6-2_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
vendor_msrc5.0MEDIUM
vendor_ubuntu4.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Routing (libssh) — CVE-2025-5987
vendor_oracle·2026-01-15·CVSS 8.1
CVE-2025-5987 [HIGH] Oracle Oracle Communications Risk Matrix: Routing (libssh) — CVE-2025-5987
Oracle Oracle Communications Risk Matrix: Routing (libssh) vulnerability
CVE: CVE-2025-5987
CVSS: 8.1
Protocol: SSH
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Microsoft
Libssh: invalid return code for chacha20 poly1305 with openssl backend
vendor_msrc·2025-07-08·CVSS 5.0
CVE-2025-5987 [HIGH] CWE-393 Libssh: invalid return code for chacha20 poly1305 with openssl backend
Libssh: invalid return code for chacha20 poly1305 with openssl backend
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Referen
Ubuntu
libssh vulnerabilities
vendor_ubuntu·2025-07-07·CVSS 4.5
CVE-2025-5351 [MEDIUM] libssh vulnerabilities
Title: libssh vulnerabilities
Summary: Several security issues were fixed in libssh.
Ronald Crane discovered that libssh incorrectly handled certain base64
conversions. An attacker could use this issue to cause libssh to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2025-4877)
Ronald Crane discovered that libssh incorrectly handled the
privatekey_from_file() function. An attacker could use this issue to cause
libssh to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-4878)
Ronald Crane discovered that libssh incorrectly handled certain memory
operations in the sftp server. An attacker could possibly use this issue
to cause libssh to crash, resulting in a denial of service.
(CVE-2025-5318, CVE-2025-5449)
Ronald C
Red Hat
libssh: Invalid return code for chacha20 poly1305 with OpenSSL backend
vendor_redhat·2025-04-26·CVSS 8.1
CVE-2025-5987 [HIGH] CWE-393 libssh: Invalid return code for chacha20 poly1305 with OpenSSL backend
libssh: Invalid return code for chacha20 poly1305 with OpenSSL backend
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes.
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cip
Debian
CVE-2025-5987: libssh - A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL libra...
vendor_debian·2025·CVSS 8.1
CVE-2025-5987 [HIGH] CVE-2025-5987: libssh - A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL libra...
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes.
Scope: local
bookworm: resolved (fixed in 0.10.6-0+deb12u2)
bullseye: resolved
forky: resolved (fixed in 0.11.2-1)
sid: resolved (fixed in 0.11.2-1)
trixie: resolved (fixed in 0.11.2-1)
OSV
libssh vulnerabilities
osv·2025-07-07·CVSS 4.5
CVE-2025-4877 [MEDIUM] libssh vulnerabilities
libssh vulnerabilities
Ronald Crane discovered that libssh incorrectly handled certain base64
conversions. An attacker could use this issue to cause libssh to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2025-4877)
Ronald Crane discovered that libssh incorrectly handled the
privatekey_from_file() function. An attacker could use this issue to cause
libssh to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2025-4878)
Ronald Crane discovered that libssh incorrectly handled certain memory
operations in the sftp server. An attacker could possibly use this issue
to cause libssh to crash, resulting in a denial of service.
(CVE-2025-5318, CVE-2025-5449)
Ronald Crane discovered that libssh incorrectly handled exporting keys.
GHSA
GHSA-3pvj-q7qj-89fg: A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library
ghsa_unreviewed·2025-07-07
CVE-2025-5987 [MEDIUM] CWE-393 GHSA-3pvj-q7qj-89fg: A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes.
OSV
CVE-2025-5987: A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library
osv·2025-07-07·CVSS 8.1
CVE-2025-5987 [HIGH] CVE-2025-5987: A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-5987 libssh: Invalid return code for chacha20 poly1305 with OpenSSL backend
bugzilla·2025-07-03·CVSS 8.1
CVE-2025-5987 [HIGH] CVE-2025-5987 libssh: Invalid return code for chacha20 poly1305 with OpenSSL backend
CVE-2025-5987 libssh: Invalid return code for chacha20 poly1305 with OpenSSL backend
If there is an error in initializing ChaCha20 cipher with OpenSSL, an invalid error code is returned. This can happen if there is an heap exhaustion. This error is not correctly detected and could allow libssh to use partially
initialized cipher context. This is caused by the mismatch of return value meaning from OpenSSL and libssh, where OpenSSL error (rv=0) aliases with SSH_OK (0) and is returned directly from the function chacha20_poly1305_set_key(). This will likely cause error somewhere down the road.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:23484 https://access.redhat.com/errata/RHSA-2025:23484
---
This issue has been addres
Bugzilla
CVE-2025-5987 mingw-libssh2: Invalid return code for chacha20 poly1305 with OpenSSL backend [fedora-42]
bugzilla·2025-07-03·CVSS 8.1
CVE-2025-5987 [HIGH] CVE-2025-5987 mingw-libssh2: Invalid return code for chacha20 poly1305 with OpenSSL backend [fedora-42]
CVE-2025-5987 mingw-libssh2: Invalid return code for chacha20 poly1305 with OpenSSL backend [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2376219
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'ver
https://access.redhat.com/errata/RHSA-2025:23483https://access.redhat.com/errata/RHSA-2025:23484https://access.redhat.com/errata/RHSA-2026:0427https://access.redhat.com/errata/RHSA-2026:0428https://access.redhat.com/errata/RHSA-2026:0430https://access.redhat.com/errata/RHSA-2026:0431https://access.redhat.com/errata/RHSA-2026:0702https://access.redhat.com/errata/RHSA-2026:0978https://access.redhat.com/errata/RHSA-2026:0980https://access.redhat.com/errata/RHSA-2026:0985https://access.redhat.com/errata/RHSA-2026:0996https://access.redhat.com/errata/RHSA-2026:1539https://access.redhat.com/errata/RHSA-2026:1541https://access.redhat.com/errata/RHSA-2026:3415https://access.redhat.com/security/cve/CVE-2025-5987https://bugzilla.redhat.com/show_bug.cgi?id=2376219https://www.libssh.org/security/advisories/CVE-2025-5987.txt
2025-07-07
Published