Logo
vulnerabilityCVE-2025-8277
Name
CVE-2025-8277
Source
NVD ( link)Debian ( link)
Description
A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
libssh
Patched

Vulnerability Ratings#


3.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.11.4
Not Affected
buildroot
master
0.12.0
Not Affected
openwrt
master
0.12.0-r1
Not Affected
openwrt
openwrt-25.12
0.11.3-r1
Not Affected
yocto
kirkstone
0.8.9
Patched
yocto
master
0.11.4
Not Affected

Resolved with patches#


libssh (yocto:kirkstone)

#
Title
Author
Resolve
1
CVE-2025-8277: ecdh: Free previously allocated pubkeys
Jakub Jelen <jjelen@redhat.com>
CVE-2025-8277
2
CVE-2025-8277: Fix memory leak of unused ephemeral key
Francesco Rollo <eferollo@gmail.com>
CVE-2025-8277
3
CVE-2025-8277: mbedtls: Avoid leaking ecdh keys
Jakub Jelen <jjelen@redhat.com>
CVE-2025-8277

libssh (yocto:scarthgap)

#
Title
Author
Resolve
1
CVE-2025-8277: Fix memory leak of unused ephemeral key pair
Francesco Rollo <eferollo@gmail.com>
CVE-2025-8277
2
CVE-2025-8277: packet: Adjust packet filter to work when DH-GEX is
Jakub Jelen <jjelen@redhat.com>
CVE-2025-8277
3
CVE-2025-8277: mbedtls: Avoid leaking ecdh keys
Jakub Jelen <jjelen@redhat.com>
CVE-2025-8277
4
CVE-2025-8277: ecdh: Free previously allocated pubkeys
Jakub Jelen <jjelen@redhat.com>
CVE-2025-8277