Double free in libssh - CVE-2025-5351
Published: September 12, 2025
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the internal function responsible for converting cryptographic keys into serialized formats. A remote user can trigger a double free error and perform a denial of service attack in low-memory scenarios.
Affected software
Ubuntu
Anolis OS
openEuler
Fedora
libssh (Ubuntu package)
libssh
libssh-help
libssh-devel
libssh-debugsource
libssh-debuginfo
libssh-config
libssh-doc
Cloud Pak for Data System - Cyclops
How to mitigate CVE-2025-5351
libssh (Ubuntu package) - addressed in versions 0.9.6-2ubuntu0.22.04.4, 0.10.6-2ubuntu0.1, 0.10.6-3ubuntu1.1, 0.11.1-1ubuntu0.1
libssh - update to 0.10.5-5
libssh-help - update to 0.10.5-5
libssh-devel - update to 0.10.5-5
libssh-debugsource - update to 0.10.5-5
libssh-debuginfo - update to 0.10.5-5
libssh-devel - update to 0.10.5-9
libssh-config - update to 0.10.5-9
libssh-doc - update to 0.10.5-9
libssh - update to 0.10.5-9
libssh - update to 0.11.2-1.fc41
Cloud Pak for Data System - Cyclops - update to 11.3.1.1