A flaw was found in libssh, a library that implements the...
Moderate severity
Unreviewed
Published
Jul 25, 2025
to the GitHub Advisory Database
•
Updated Jul 25, 2025
Description
Published by the National Vulnerability Database
Jul 24, 2025
Published to the GitHub Advisory Database
Jul 25, 2025
Last updated
Jul 25, 2025
A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.
References