PT-2026-64380 · Libssh2+2 · Libssh2+2
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
libssh2 versions prior to 1.11.1
Description
A pre-authentication integer underflow exists in the
ssh2 cipher crypt() function within src/openssl.c. A malicious SSH server can trigger this issue during the handshake by negotiating AES-GCM ciphers. The underflow occurs during the calculation of blocksize minus aadlen minus authentication tag length, leading to an out-of-bounds read and a memcpy call with a length argument near SIZE MAX, which results in an immediate process crash.Recommendations
Update to the version containing commit a2ed82d.
Exploit
Fix
DoS
Integer Underflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Libssh2