Out-of-bounds read in libssh - CVE-2025-5318

 

Out-of-bounds read in libssh - CVE-2025-5318

Published: June 24, 2025


Vulnerability identifier: #VU111900
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-5318
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the sftp_handle() function. A remote user can trigger an out-of-bounds read error and read contents of memory on the system.


Affected software

libssh
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
openEuler
Fedora
IBM Observability with Instana
Oracle Communications Unified Inventory Management
Oracle Communications LSMS
Oracle Blockchain Platform
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Network Repository Function
Splunk Operator for Kubernetes Add-on
Financial Transaction Manager for RedHat OpenShift
Oracle Enterprise Communications Broker
Storage Virtualize
Total Storage Service Console (TSSC) / TS4500 IMC
Verify Identity Access Digital Credentials
Oracle Communications EAGLE LNP Application Processor
Oracle Communications Policy Management
Oracle Communications EAGLE Application Processor
Business Automation Insights
Cloud Pak for Data System - Cyclops
Communications Unified Assurance
LANTIME Operating System Firmware (LTOS)
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
MySQL Cluster
RSA Authentication Manager
MySQL Workbench
IBM CICS TX Standard
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libssh (Ubuntu package)
libssh-devel-doc
libssh (Red Hat package)
libssh
libssh-debuginfo
libssh-help
libssh-devel
libssh-debugsource
libssh-doc
libssh-config
Oracle Communications Session Border Controller
IBM Security Verify Access
Juniper Junos Space
Oracle Communications Pricing Design Center
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Service Communication Proxy
Red Hat OpenShift Serverless
Red Hat OpenShift Container Platform

How to mitigate CVE-2025-5318

Install updates from vendor's website.

libssh - update to 0.11.2
IBM Observability with Instana - update to 1.0.313
LANTIME Operating System Firmware (LTOS) - update to 7.08.025
Juniper Secure Analytics (JSA) - update to 7.5.0 UP14 IF01
IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF01
RSA Authentication Manager - update to 8.8 Patch 2
Storage Virtualize - addressed in versions 8.7.0.8, 9.1.0.2
Business Automation Insights - addressed in versions 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3
libssh (Ubuntu package) - addressed in versions 0.6.3-4.3ubuntu0.6+esm2, 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4, 0.9.3-2ubuntu2.5+esm1, 0.9.6-2ubuntu0.22.04.4, 0.10.6-2ubuntu0.1, 0.10.6-3ubuntu1.1, 0.11.1-1ubuntu0.1
libssh-devel-doc - update to 0.6.3-12.15.1
libssh (Red Hat package) - addressed in versions 0.9.0-4.el8_2.1, 0.9.4-2.el8_4.1, 0.9.6-3.el9_0.1, 0.9.6-4.el8_6.1, 0.9.6-13.el8_8.1, 0.9.6-15.el8_10, 0.10.4-9.el9_2.1, 0.10.4-13.el9_4.1, 0.10.4-15.el9_6, 0.11.1-4.el10_0
libssh - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-debuginfo - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-help - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-devel - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-debugsource - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-doc - addressed in versions 0.9.6-15.0.1, 0.10.5-6
libssh - addressed in versions 0.9.6-15.0.1, 0.10.5-6
libssh-config - addressed in versions 0.9.6-15.0.1, 0.10.5-6
libssh-devel - addressed in versions 0.9.6-15.0.1, 0.10.5-6
libssh - addressed in versions 0.11.2-1.fc41, 0.11.2-1.fc42
Red Hat OpenShift Serverless - update to 1
Splunk Operator for Kubernetes Add-on - update to 3.1.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.83, 4.13.62, 4.14.59, 4.15.61, 4.16.55, 4.17.43, 4.18.28, 4.19.18, 4.20.2
IBM CICS TX Standard - update to 11.1.0.0 ifix41
Cloud Pak for Data System - Cyclops - update to 11.3.1.1
Juniper Junos Space - update to 26.1R1 Patch V1

External References

Related Security Bulletins