Medium severity4.7OSV Advisory· Published Jul 24, 2025· Updated Jun 30, 2026
CVE-2025-8114
CVE-2025-8114
Description
A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
22- osv-coords19 versionspkg:apk/chainguard/libsshpkg:apk/chainguard/libssh-devpkg:apk/wolfi/libsshpkg:apk/wolfi/libssh-devpkg:rpm/almalinux/libsshpkg:rpm/almalinux/libssh-configpkg:rpm/almalinux/libssh-develpkg:rpm/opensuse/libssh&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/libssh&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libssh&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/libssh&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/libssh&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/libssh&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/libssh&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/libssh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/libssh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7pkg:rpm/suse/libssh&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/libssh&distro=SUSE%20Linux%20Micro%206.0pkg:rpm/suse/libssh&distro=SUSE%20Linux%20Micro%206.1
< 0.11.3-r0+ 18 more
- (no CPE)range: < 0.11.3-r0
- (no CPE)range: < 0.11.3-r0
- (no CPE)range: < 0.11.3-r0
- (no CPE)range: < 0.11.3-r0
- (no CPE)range: < 0.10.4-18.el9
- (no CPE)range: < 0.10.4-18.el9
- (no CPE)range: < 0.10.4-18.el9
- (no CPE)range: < 0.9.8-150600.11.6.1
- (no CPE)range: < 0.11.3-1.1
- (no CPE)range: < 0.9.8-150200.13.12.1
- (no CPE)range: < 0.9.8-150200.13.12.1
- (no CPE)range: < 0.9.8-150400.3.12.1
- (no CPE)range: < 0.9.8-150400.3.12.1
- (no CPE)range: < 0.9.8-150400.3.12.1
- (no CPE)range: < 0.9.8-150600.11.6.1
- (no CPE)range: < 0.9.8-150600.11.6.1
- (no CPE)range: < 0.9.8-3.18.1
- (no CPE)range: < 0.10.6-3.1
- (no CPE)range: < 0.10.6-slfo.1.1_3.1
Patches
Vulnerability mechanics
References
6- access.redhat.com/security/cve/CVE-2025-8114nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- access.redhat.com/errata/RHSA-2026:18683nvd
- git.libssh.org/projects/libssh.git/commit/nvd
- git.libssh.org/projects/libssh.git/commit/nvd
- www.libssh.org/security/advisories/CVE-2025-8114.txtnvd
News mentions
0No linked articles in our index yet.