CVE-2025-5318 @ Saiph
Status
accepted_risk
Priority
1.21
Match score
4.0
Risk
InfoLeak
MemCorrupt
Remote
priv:user
CVSS
5.4 MEDIUM
Reason
cpe: libssh; pkgs: libssh-gcrypt-4; version: in-range: libssh-gcrypt-4-0.8.7-1+deb10u2; risk:info_disclosure
Created
2026-08-03T20:47:05Z
Updated
2026-08-04T20:04:00Z
Closed
2026-08-04T20:04:00Z
Package interrogation (copy)
Run on the host — click to copy a command. Debian/apt
| Package | Commands |
|---|---|
| libssh-gcrypt-4-0.8.7-1+deb10u2 | |
| libssh-gcrypt-4 | |
| libssh |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: libssh-gcrypt · libssh · libssh-gcrypt-4
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2026-66032 | 8.8 | Helios, morris, mufasa | accepted_risk | libssh | — | ||
| CVE-2026-59851 | 8.8 | Saiph | not_applicable | libssh-gcrypt | — | ||
| CVE-2026-0966 | 8.2 | Saiph | new | libssh-gcrypt | — | ||
| CVE-2026-66033 | 7.5 | Helios, morris, mufasa | accepted_risk | libssh | — | ||
| CVE-2026-66034 | 7.5 | Helios, morris, mufasa | accepted_risk, not_applicable | libssh | → CVE-2026-66033 | ||
| CVE-2026-66035 | 7.5 | morris, mufasa | not_applicable | libssh | → CVE-2026-66033 |
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Host OS / kernel
OS
Debian GNU/Linux 10 (buster)
(10)
· debian
Arch
x86_64
kernel_release
uname -r → 4.19.0-27-amd64kernel_version
uname -v → #1 SMP Debian 4.19.316-1 (2024-06-25)For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Description
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.
Determination
libssh-gcrypt-40.8.7-1+deb10u2 : Vulnerable libssh (related)0.8.7 series: Vulnerable Practical Risk Requires authenticated access to an SFTP service that uses libssh. Not remotely exploitable by anonymous users.
Update status
Add note only
Mitigation log
2026-08-04T20:03:44Z — affects
libssh-gcrypt-40.8.7-1+deb10u2 : Vulnerable
libssh (related)0.8.7 series: Vulnerable
2026-08-04T20:04:00Z — accepted_risk
Practical Risk
Requires authenticated access to an SFTP service that uses libssh.
Not remotely exploitable by anonymous users.
References
- https://access.redhat.com/errata/RHSA-2025:18231
- https://access.redhat.com/errata/RHSA-2025:18275
- https://access.redhat.com/errata/RHSA-2025:18286
- https://access.redhat.com/errata/RHSA-2025:19012
- https://access.redhat.com/errata/RHSA-2025:19098
- https://access.redhat.com/errata/RHSA-2025:19101
- https://access.redhat.com/errata/RHSA-2025:19295
- https://access.redhat.com/errata/RHSA-2025:19300
- https://access.redhat.com/errata/RHSA-2025:19313
- https://access.redhat.com/errata/RHSA-2025:19400
- https://access.redhat.com/errata/RHSA-2025:19401
- https://access.redhat.com/errata/RHSA-2025:19470
- https://access.redhat.com/errata/RHSA-2025:19472
- https://access.redhat.com/errata/RHSA-2025:19807
- https://access.redhat.com/errata/RHSA-2025:19864
NVD: CVE-2025-5318