PT-2026-53083 · Libssh2+3 · Libssh2+3
CVSS v4.0
8.3
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
libssh2 versions prior to 1.11.2
Description
An issue exists in the public key parsing process where the software expands its public key list using
SSH2 REALLOC but fails to zero-initialize new entries before they are populated. If a parse failure occurs and triggers the cleanup path, the libssh2 publickey list free() function may operate on an uninitialized entry. A malicious SSH server providing the public key subsystem can send a malformed response to cause the client to free an uninitialized attrs pointer, leading to a use-after-free condition.Recommendations
Update libssh2 to version 1.11.2 or later.
Exploit
Fix
DoS
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Libssh2