Incorrect calculation in libssh - CVE-2025-5372

 

Incorrect calculation in libssh - CVE-2025-5372

Published: August 14, 2025 / Updated: February 24, 2026


Vulnerability identifier: #VU114093
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L]
CVE-ID: CVE-2025-5372
CWE-ID: CWE-682
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform MitM attack.

The vulnerability exist due to incorrect calculation within the ssh_kdf() function responsible for key derivation when built with OpenSSL versions older than 3.0. A remote user can compromise the integrity of the SSH session. 


Affected software

libssh
Financial Transaction Manager for RedHat OpenShift
CICS Transaction Gateway for Multiplatforms
Total Storage Service Console (TSSC) / TS4500 IMC
Cloud Pak for Data System - Cyclops
Communications Unified Assurance
IBM Qradar SIEM
RSA Authentication Manager
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Ubuntu
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libssh (Red Hat package)
libssh (Ubuntu package)
libssh-doc
libssh-config
libssh-devel
libssh
libssh-help
libssh-debugsource
libssh-debuginfo
Siebel CRM Cloud Applications
Red Hat OpenShift Serverless
Splunk Operator for Kubernetes Add-on
IBM Power Hardware Management Console (HMC)
IBM CICS TX Standard

How to mitigate CVE-2025-5372

Rebuild your libssh with OpenSSL 3.0+ to resolve the issue.

IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF03
RSA Authentication Manager - update to 8.8 Patch 2
libssh (Red Hat package) - addressed in versions 0.9.4-2.el8_4.2, 0.9.6-3.el9_0.2, 0.9.6-4.el8_6.2, 0.9.6-16.el8_10
libssh (Ubuntu package) - addressed in versions 0.9.6-2ubuntu0.22.04.4, 0.10.6-2ubuntu0.1, 0.10.6-3ubuntu1.1, 0.11.1-1ubuntu0.1
libssh-doc - addressed in versions 0.9.6-16.0.1, 0.10.5-7
libssh-config - addressed in versions 0.9.6-16.0.1, 0.10.5-7
libssh-devel - addressed in versions 0.9.6-16.0.1, 0.10.5-7
libssh - addressed in versions 0.9.6-16.0.1, 0.10.5-7
libssh-help - update to 0.10.5-5
libssh-devel - update to 0.10.5-5
libssh-debugsource - update to 0.10.5-5
libssh-debuginfo - update to 0.10.5-5
libssh - update to 0.10.5-5
libssh - update to 0.11.2-1.fc41
Red Hat OpenShift Serverless - update to 1
Splunk Operator for Kubernetes Add-on - update to 3.1.0
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1063.2, 11.1.1111.5
IBM CICS TX Standard - update to 11.1.0.0 ifix41
Cloud Pak for Data System - Cyclops - update to 11.3.1.1

External References

Related Security Bulletins