VDB

CISA-2025-5372

CISA-2025-5372 PUBLISHED CVSS 5 MEDIUM

Reported by redhat · Published July 4, 2025

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.

Risk Scores

CVSS 3.1
5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected Products

VendorProductVersions
libsshlibssh0
Red HatRed Hat Enterprise Linux 80:0.9.6-16.el8_10
Red HatRed Hat Enterprise Linux 80:0.9.6-16.el8_10
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutions0:0.9.6-3.el9_0.2
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutions0:0.9.6-3.el9_0.2, 0:0.9.6-3.el9_0.2
Red HatRed Hat Enterprise Linux 80:0.9.6-16.el8_10, 0:0.9.6-16.el8_10, 0:0.9.6-16.el8_10
Red HatRed Hat Enterprise Linux 10
libsshlibssh0, 0

Timeline

  • Jul 4, 2025 CVE Published
  • Mar 10, 2026 CVE Updated
  • Apr 26, 2026 Distribution Patch
  • Apr 26, 2026 Distribution Patch
  • Apr 26, 2026 Security Advisory
  • Apr 26, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›