VDB

DEBIAN-CVE-2025-5372

DEBIAN-CVE-2025-5372 PUBLISHED CVSS 8.800000190734863 HIGH

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:13libssh0, 0
Debian:14libssh0, 0
Debian:12libssh0.10.6-0+deb12u1, 0, 0.10.5-2
Debian:11libssh0.9.6-2, 0.9.7-0+deb11u1, 0.9.8-0+deb11u1

Timeline

  • Jul 4, 2025 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›