cbcvebase.
CVE-2025-5987
published 2025-07-07

CVE-2025-5987: A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not…

PriorityP350high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.44%
70.2th percentile
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlibssh< libssh 0.10.6-0+deb12u2 (bookworm)libssh 0.10.6-0+deb12u2 (bookworm)
libsshlibssh>= 0 < 0.10.6-0+deb12u20.10.6-0+deb12u2
libsshlibssh>= 0 < 0.11.2-10.11.2-1
libsshlibssh>= 0 < 0.11.2-10.11.2-1
libsshlibssh>= 0 < 0.9.6-2ubuntu0.22.04.40.9.6-2ubuntu0.22.04.4
libsshlibssh>= 0 < 0.10.6-2ubuntu0.10.10.6-2ubuntu0.1
libsshlibssh>= 0.10.0 < 0.11.20.11.2
msrcazl3_libssh_0.10.6-1_on_azure_linux_3.0
msrcazl3_libssh_0.10.6-2_on_azure_linux_3.0
msrccbl2_libssh_0.10.6-1_on_cbl_mariner_2.0
msrccbl2_libssh_0.10.6-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
vendor_msrc5.0MEDIUM
vendor_ubuntu4.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.