🔐 CVE Alert

CVE-2025-5372

MEDIUM 5.0

Libssh: incorrect return code handling in ssh_kdf() in libssh

CVSS Score
5.0
EPSS Score
0.1%
EPSS Percentile
28th

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.

CWE CWE-682
Vendor libssh
Product libssh
Published Jul 4, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for libssh libssh

Be the first to know when new medium vulnerabilities affecting libssh libssh are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

libssh / libssh
0 < 0.11.2
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 6
All versions affected
Red Hat / Red Hat Enterprise Linux 7
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected

References

NVD ↗ CVE.org ↗ EPSS Data ↗
access.redhat.com: https://access.redhat.com/errata/RHSA-2025:21977 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:23024 access.redhat.com: https://access.redhat.com/security/cve/CVE-2025-5372 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2369388