CVE-2025-8114

A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*

History

17 Nov 2025, 21:15

Type Values Removed Values Added
References
  • () https://git.libssh.org/projects/libssh.git/commit/?id=65f363c9 -

17 Nov 2025, 20:15

Type Values Removed Values Added
References
  • () https://git.libssh.org/projects/libssh.git/commit/?id=53ac23ded4cb2c5463f6c4cd1525331bd578812d -
  • () https://www.libssh.org/security/advisories/CVE-2025-8114.txt -

14 Aug 2025, 00:45

Type Values Removed Values Added
CPE cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
First Time Libssh libssh
Libssh
Summary
  • (es) Se encontró una falla en libssh, una librería que implementa el protocolo SSH. Al calcular el ID de sesión durante el proceso de intercambio de claves (KEX), un fallo de asignación en las funciones criptográficas puede provocar una desreferencia de puntero nulo. Este problema puede provocar el bloqueo del cliente o del servidor.
References () https://access.redhat.com/security/cve/CVE-2025-8114 - () https://access.redhat.com/security/cve/CVE-2025-8114 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2383220 - () https://bugzilla.redhat.com/show_bug.cgi?id=2383220 - Issue Tracking, Third Party Advisory

24 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-24 15:15

Updated : 2025-11-17 21:15


NVD link : CVE-2025-8114

Mitre link : CVE-2025-8114

CVE.ORG link : CVE-2025-8114


JSON object : View

Products Affected

libssh

  • libssh
CWE
CWE-476

NULL Pointer Dereference