Out-of-bounds read in libssh - CVE-2025-5318
Published: June 24, 2025
Vulnerability identifier: #VU111900
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-5318
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the sftp_handle() function. A remote user can trigger an out-of-bounds read error and read contents of memory on the system.
Affected software
libssh
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
openEuler
Fedora
IBM Observability with Instana
Oracle Communications Unified Inventory Management
Oracle Communications LSMS
Oracle Blockchain Platform
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Network Repository Function
Splunk Operator for Kubernetes Add-on
Financial Transaction Manager for RedHat OpenShift
Oracle Enterprise Communications Broker
Storage Virtualize
Total Storage Service Console (TSSC) / TS4500 IMC
Verify Identity Access Digital Credentials
Oracle Communications EAGLE LNP Application Processor
Oracle Communications Policy Management
Oracle Communications EAGLE Application Processor
Business Automation Insights
Cloud Pak for Data System - Cyclops
Communications Unified Assurance
LANTIME Operating System Firmware (LTOS)
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
MySQL Cluster
RSA Authentication Manager
MySQL Workbench
IBM CICS TX Standard
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libssh (Ubuntu package)
libssh-devel-doc
libssh (Red Hat package)
libssh
libssh-debuginfo
libssh-help
libssh-devel
libssh-debugsource
libssh-doc
libssh-config
Oracle Communications Session Border Controller
IBM Security Verify Access
Juniper Junos Space
Oracle Communications Pricing Design Center
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Service Communication Proxy
Red Hat OpenShift Serverless
Red Hat OpenShift Container Platform
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
openEuler
Fedora
IBM Observability with Instana
Oracle Communications Unified Inventory Management
Oracle Communications LSMS
Oracle Blockchain Platform
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Network Repository Function
Splunk Operator for Kubernetes Add-on
Financial Transaction Manager for RedHat OpenShift
Oracle Enterprise Communications Broker
Storage Virtualize
Total Storage Service Console (TSSC) / TS4500 IMC
Verify Identity Access Digital Credentials
Oracle Communications EAGLE LNP Application Processor
Oracle Communications Policy Management
Oracle Communications EAGLE Application Processor
Business Automation Insights
Cloud Pak for Data System - Cyclops
Communications Unified Assurance
LANTIME Operating System Firmware (LTOS)
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
MySQL Cluster
RSA Authentication Manager
MySQL Workbench
IBM CICS TX Standard
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libssh (Ubuntu package)
libssh-devel-doc
libssh (Red Hat package)
libssh
libssh-debuginfo
libssh-help
libssh-devel
libssh-debugsource
libssh-doc
libssh-config
Oracle Communications Session Border Controller
IBM Security Verify Access
Juniper Junos Space
Oracle Communications Pricing Design Center
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Service Communication Proxy
Red Hat OpenShift Serverless
Red Hat OpenShift Container Platform
How to mitigate CVE-2025-5318
Install updates from vendor's website.
libssh - update to 0.11.2
IBM Observability with Instana - update to 1.0.313
LANTIME Operating System Firmware (LTOS) - update to 7.08.025
Juniper Secure Analytics (JSA) - update to 7.5.0 UP14 IF01
IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF01
RSA Authentication Manager - update to 8.8 Patch 2
Storage Virtualize - addressed in versions 8.7.0.8, 9.1.0.2
Business Automation Insights - addressed in versions 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3
libssh (Ubuntu package) - addressed in versions 0.6.3-4.3ubuntu0.6+esm2, 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4, 0.9.3-2ubuntu2.5+esm1, 0.9.6-2ubuntu0.22.04.4, 0.10.6-2ubuntu0.1, 0.10.6-3ubuntu1.1, 0.11.1-1ubuntu0.1
libssh-devel-doc - update to 0.6.3-12.15.1
libssh (Red Hat package) - addressed in versions 0.9.0-4.el8_2.1, 0.9.4-2.el8_4.1, 0.9.6-3.el9_0.1, 0.9.6-4.el8_6.1, 0.9.6-13.el8_8.1, 0.9.6-15.el8_10, 0.10.4-9.el9_2.1, 0.10.4-13.el9_4.1, 0.10.4-15.el9_6, 0.11.1-4.el10_0
libssh - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-debuginfo - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-help - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-devel - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-debugsource - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-doc - addressed in versions 0.9.6-15.0.1, 0.10.5-6
libssh - addressed in versions 0.9.6-15.0.1, 0.10.5-6
libssh-config - addressed in versions 0.9.6-15.0.1, 0.10.5-6
libssh-devel - addressed in versions 0.9.6-15.0.1, 0.10.5-6
libssh - addressed in versions 0.11.2-1.fc41, 0.11.2-1.fc42
Red Hat OpenShift Serverless - update to 1
Splunk Operator for Kubernetes Add-on - update to 3.1.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.83, 4.13.62, 4.14.59, 4.15.61, 4.16.55, 4.17.43, 4.18.28, 4.19.18, 4.20.2
IBM CICS TX Standard - update to 11.1.0.0 ifix41
Cloud Pak for Data System - Cyclops - update to 11.3.1.1
Juniper Junos Space - update to 26.1R1 Patch V1
IBM Observability with Instana - update to 1.0.313
LANTIME Operating System Firmware (LTOS) - update to 7.08.025
Juniper Secure Analytics (JSA) - update to 7.5.0 UP14 IF01
IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF01
RSA Authentication Manager - update to 8.8 Patch 2
Storage Virtualize - addressed in versions 8.7.0.8, 9.1.0.2
Business Automation Insights - addressed in versions 24.0.0.0.6, 24.0.1.0.6, 25.0.0.0.3
libssh (Ubuntu package) - addressed in versions 0.6.3-4.3ubuntu0.6+esm2, 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4, 0.9.3-2ubuntu2.5+esm1, 0.9.6-2ubuntu0.22.04.4, 0.10.6-2ubuntu0.1, 0.10.6-3ubuntu1.1, 0.11.1-1ubuntu0.1
libssh-devel-doc - update to 0.6.3-12.15.1
libssh (Red Hat package) - addressed in versions 0.9.0-4.el8_2.1, 0.9.4-2.el8_4.1, 0.9.6-3.el9_0.1, 0.9.6-4.el8_6.1, 0.9.6-13.el8_8.1, 0.9.6-15.el8_10, 0.10.4-9.el9_2.1, 0.10.4-13.el9_4.1, 0.10.4-15.el9_6, 0.11.1-4.el10_0
libssh - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-debuginfo - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-help - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-devel - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-debugsource - addressed in versions 0.9.4-10, 0.9.6-10, 0.10.5-4
libssh-doc - addressed in versions 0.9.6-15.0.1, 0.10.5-6
libssh - addressed in versions 0.9.6-15.0.1, 0.10.5-6
libssh-config - addressed in versions 0.9.6-15.0.1, 0.10.5-6
libssh-devel - addressed in versions 0.9.6-15.0.1, 0.10.5-6
libssh - addressed in versions 0.11.2-1.fc41, 0.11.2-1.fc42
Red Hat OpenShift Serverless - update to 1
Splunk Operator for Kubernetes Add-on - update to 3.1.0
Red Hat OpenShift Container Platform - addressed in versions 4.12.83, 4.13.62, 4.14.59, 4.15.61, 4.16.55, 4.17.43, 4.18.28, 4.19.18, 4.20.2
IBM CICS TX Standard - update to 11.1.0.0 ifix41
Cloud Pak for Data System - Cyclops - update to 11.3.1.1
Juniper Junos Space - update to 26.1R1 Patch V1
External References
Related Security Bulletins
- Information disclosure in libssh
- Fedora 42 update for libssh
- openEuler 20.03 LTS SP4 update for libssh
- openEuler 24.03 LTS update for libssh
- openEuler 22.03 LTS SP4 update for libssh
- openEuler 22.03 LTS SP3 update for libssh
- openEuler 24.03 LTS SP2 update for libssh
- openEuler 24.03 LTS SP1 update for libssh
- Anolis OS update for libssh
- SUSE update for libssh
- RSA Authentication Manager update for third-party components
- Ubuntu update for libssh
- Multiple vulnerabilities in Meinberg LANTIME firmware
- Fedora 41 update for libssh
- Ubuntu update for libssh
- Red Hat Enterprise Linux 10 update for libssh
- Red Hat Enterprise Linux 9 update for libssh
- Red Hat Enterprise Linux 8 update for libssh
- Multiple vulnerabilities in Oracle Communications Unified Inventory Management
- Multiple vulnerabilities in MySQL Workbench
- Anolis OS update for libssh
- Red Hat Enterprise Linux 8 update for libssh
- Red Hat Enterprise Linux 8 update for libssh
- IBM Financial Transaction Manager (FTM) for RedHat OpenShift update for libssh library
- Red Hat Enterprise Linux 8 update for libssh
- Red Hat Enterprise Linux 8 update for libssh
- Red Hat Enterprise Linux 9 update for libssh
- Red Hat Enterprise Linux 9 update for libssh
- Red Hat Enterprise Linux 9 update for libssh
- Out-of-bounds read in Red Hat OpenShift Container Platform 4.20
- Out-of-bounds read in Red Hat OpenShift Container Platform 4.17
- Out-of-bounds read in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in IBM Storage Virtualize
- Out-of-bounds read in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM QRadar SIEM
- Out-of-bounds read in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Total Storage Service Console (TSSC) / TS4500 IMC update for libssh
- Multiple vulnerabilities in IBM Verify Identity Access and IBM Security Verify Access
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Out-of-bounds read in Oracle Communications Pricing Design Center
- Multiple vulnerabilities in Oracle Communications Policy Management
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Oracle Communications Network Analytics Data Director
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Juniper Secure Analytics update for third-party components
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Observability with Instana
- Splunk Operator for Kubernetes Add-on update for third-party components
- Multiple vulnerabilities in Oracle Blockchain Platform
- Out-of-bounds read in Oracle Enterprise Communications Broker
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Out-of-bounds read in Oracle Communications Session Border Controller
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in Oracle Communications EAGLE LNP Application Processor
- Multiple vulnerabilities in Oracle Communications EAGLE Application Processor
- Multiple vulnerabilities in Oracle Communications LSMS
- Out-of-bounds read in MySQL Cluster
- Multiple vulnerabilities in IBM CICS TX Standard
- Multiple vulnerabilities in IBM Cloud Pak for Data System - Cyclops
- Multiple vulnerabilities in Junos Space