ITSECURITYWHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardVulnerabilities › CVE-2025-5372
8.8High CVE-2025-5372 Libssh

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key d

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographi

What happened

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.

Does it affect you

Not enough information

No products recorded, so this cannot be matched against anything.

What to do

The vendor has not published remediation yet. We do not invent it.

Vendor's affected list

rhel
Exactly 6.0

Sources

A verdict here is derived from what you told us and what the vendor published. It is not an assessment of your environment. Why we never say you are safe.