Logo
vulnerabilityCVE-2025-5318
Name
CVE-2025-5318
Source
NVD ( link)Debian ( link)
Description
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libssh
Patched

Vulnerability Ratings#


8.1
CVSSv31
8.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.11.4
Not Affected
buildroot
master
0.12.0
Not Affected
openwrt
master
0.12.0-r1
Not Affected
openwrt
openwrt-25.12
0.11.3-r1
Not Affected
yocto
master
0.11.4
Not Affected
yocto
scarthgap
0.10.6
Patched

Resolved with patches#


libssh (yocto:kirkstone)

#
Title
Author
Resolve
1
CVE-2025-5318: sftpserver: Fix possible buffer overrun
Jakub Jelen <jjelen@redhat.com>
CVE-2025-5318

libssh (yocto:scarthgap)

#
Title
Author
Resolve
1
CVE-2025-5318: sftpserver: Fix possible buffer overrun
Jakub Jelen <jjelen@redhat.com>
CVE-2025-5318