Libssh: integer overflow in libssh sftp server packet length validation leading to denial of service

CVE Details

Basic Information

Title Libssh: integer overflow in libssh sftp server packet length validation leading to denial of service
Type cve
Published 2025-07-25T17:19:39.345Z
Modified 2025-07-25T17:34:41.318Z

Product Information

Version 0.11.0

CVSS Information

Base Score 4.3 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected Products

  • 0.11.0

Additional Information

CWE List CWE-190
Source redhat

Description

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads to failed memory allocation and causes the server process to crash, resulting in a denial of service.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.