#VU115173 NULL pointer dereference in libssh - CVE-2025-8114
Published: September 12, 2025 / Updated: February 24, 2026
libssh
libssh
Description
The vulnerability allows a remote attack to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error when calculating the session ID during the key exchange (KEX) process. A remote attacker can trick the victim into connecting to a malicious SSH server and crash the client app.