NULL pointer dereference in libssh - CVE-2025-8114
Published: September 12, 2025 / Updated: February 24, 2026
Vulnerability details
The vulnerability allows a remote attack to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error when calculating the session ID during the key exchange (KEX) process. A remote attacker can trick the victim into connecting to a malicious SSH server and crash the client app.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Micro
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
Fedora
LANTIME Operating System Firmware (LTOS)
libssh (Ubuntu package)
libssh-devel-doc
libssh-debuginfo
libssh-debugsource
libssh-devel
libssh-help
libssh
libssh4-32bit
libssh-config
libssh4
libssh4-debuginfo-32bit
libssh4-debuginfo
libssh4-64bit-debuginfo
libssh4-64bit
libssh4-32bit-debuginfo
libssh-doc
Cloud Pak for Data System - Cyclops
How to mitigate CVE-2025-8114
LANTIME Operating System Firmware (LTOS) - update to 7.10.004
libssh (Ubuntu package) - addressed in versions 0.6.3-4.3ubuntu0.6+esm3, 0.8.0~20170825.94fa1e38-1ubuntu0.7+esm5, 0.9.3-2ubuntu2.5+esm2, 0.9.6-2ubuntu0.22.04.5, 0.10.6-2ubuntu0.2, 0.11.1-1ubuntu0.2, 0.11.2-1ubuntu0.1
libssh-devel-doc - update to 0.6.3-12.21.1
libssh-debuginfo - update to 0.9.6-12
libssh-debugsource - update to 0.9.6-12
libssh-devel - update to 0.9.6-12
libssh-help - update to 0.9.6-12
libssh - update to 0.9.6-12
libssh4-32bit - addressed in versions 0.9.8-3.18.1, 0.9.8-150400.3.12.1, 0.9.8-150600.11.6.1
libssh-config - addressed in versions 0.9.8-3.18.1, 0.9.8-150200.13.12.1, 0.9.8-150400.3.12.1, 0.9.8-150600.11.6.1, 0.11.4-160000.1.1
libssh4 - addressed in versions 0.9.8-3.18.1, 0.9.8-150200.13.12.1, 0.9.8-150400.3.12.1, 0.9.8-150600.11.6.1, 0.11.4-160000.1.1
libssh-debugsource - addressed in versions 0.9.8-3.18.1, 0.9.8-150200.13.12.1, 0.9.8-150400.3.12.1, 0.9.8-150600.11.6.1, 0.11.4-160000.1.1
libssh4-debuginfo-32bit - update to 0.9.8-3.18.1
libssh4-debuginfo - addressed in versions 0.9.8-3.18.1, 0.9.8-150200.13.12.1, 0.9.8-150400.3.12.1, 0.9.8-150600.11.6.1, 0.11.4-160000.1.1
libssh-devel - addressed in versions 0.9.8-3.18.1, 0.9.8-150400.3.12.1, 0.9.8-150600.11.6.1
libssh4-64bit-debuginfo - addressed in versions 0.9.8-150400.3.12.1, 0.9.8-150600.11.6.1
libssh4-64bit - addressed in versions 0.9.8-150400.3.12.1, 0.9.8-150600.11.6.1
libssh4-32bit-debuginfo - addressed in versions 0.9.8-150400.3.12.1, 0.9.8-150600.11.6.1
libssh - update to 0.10.5-11
libssh-devel - update to 0.10.5-11
libssh-config - update to 0.10.5-11
libssh-doc - update to 0.10.5-11
libssh - addressed in versions 0.11.3-1.fc41, 0.11.3-1.fc42, 0.11.3-1.fc43
Cloud Pak for Data System - Cyclops - update to 11.3.1.1
External References
Related Security Bulletins
- Denial of service in libssh
- Fedora 43 update for libssh
- Fedora 42 update for libssh
- Fedora 41 update for libssh
- openEuler update for libssh
- SUSE update for libssh
- SUSE update for libssh
- SUSE update for libssh
- SUSE update for libssh
- Anolis OS update for libssh
- Meinberg LANTIME firmware update for third-party components
- Ubuntu update for libssh
- SUSE update for libssh
- SUSE update for libssh
- Multiple vulnerabilities in IBM Cloud Pak for Data System - Cyclops