Logo
vulnerabilityCVE-2025-5351
Name
CVE-2025-5351
Source
NVD ( link)Debian ( link)
Description
A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libssh
Patched

Vulnerability Ratings#


6.5
CVSSv31
6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.11.4
Not Affected
buildroot
master
0.12.0
Not Affected
openwrt
master
0.12.0-r1
Not Affected
openwrt
openwrt-25.12
0.11.3-r1
Not Affected
yocto
kirkstone
0.8.9
Not Affected
yocto
master
0.11.4
Not Affected

Resolved with patches#


libssh (yocto:scarthgap)

#
Title
Author
Resolve
1
CVE-2025-5351 pki_crypto: Avoid double-free on low-memory conditions
Jakub Jelen <jjelen@redhat.com>
CVE-2025-5351