Integer overflow in libssh - CVE-2025-4877

 

Integer overflow in libssh - CVE-2025-4877

Published: August 12, 2025


Vulnerability identifier: #VU113839
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-4877
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow within the bin_to_base64() function in base64.c. A local user can trigger an integer overflow and execute arbitrary code on the target system.

Note, the vulnerability can be exploited only via the ssh_get_fingerprint_hash() function on 32-bit builds in case the API is (mis)used and a libssh consumer passes in an unexpectedly large input buffer.


Affected software

libssh
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
Ubuntu
openEuler
Fedora
IBM Observability with Instana
libssh (Ubuntu package)
libssh-devel-doc
libssh
libssh-help
libssh-devel
libssh-debugsource
libssh-debuginfo

How to mitigate CVE-2025-4877

Install updates from vendor's website.

libssh - update to 0.11.2
IBM Observability with Instana - update to 1.0.313
libssh (Ubuntu package) - addressed in versions 0.6.3-4.3ubuntu0.6+esm2, 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4, 0.9.3-2ubuntu2.5+esm1, 0.9.6-2ubuntu0.22.04.4, 0.10.6-2ubuntu0.1, 0.10.6-3ubuntu1.1, 0.11.1-1ubuntu0.1
libssh-devel-doc - update to 0.6.3-12.15.1
libssh - update to 0.10.5-5
libssh-help - update to 0.10.5-5
libssh-devel - update to 0.10.5-5
libssh-debugsource - update to 0.10.5-5
libssh-debuginfo - update to 0.10.5-5
libssh - update to 0.11.2-1.fc41

External References

Related Security Bulletins