CVE Tracker

CVE-2025-5318 @ Saiph

Status
accepted_risk
Priority
1.21
Match score
4.0
Risk
InfoLeak MemCorrupt Remote priv:user
CVSS
5.4 MEDIUM
Reason
cpe: libssh; pkgs: libssh-gcrypt-4; version: in-range: libssh-gcrypt-4-0.8.7-1+deb10u2; risk:info_disclosure
Created
2026-08-03T20:47:05Z
Updated
2026-08-04T20:04:00Z
Closed
2026-08-04T20:04:00Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
libssh-gcrypt-4-0.8.7-1+deb10u2
libssh-gcrypt-4
libssh

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Suggestions: libssh-gcrypt · libssh · libssh-gcrypt-4

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-66032 8.8 Helios, morris, mufasa accepted_risk libssh
CVE-2026-59851 8.8 Saiph not_applicable libssh-gcrypt
CVE-2026-0966 8.2 Saiph new libssh-gcrypt
CVE-2026-66033 7.5 Helios, morris, mufasa accepted_risk libssh
CVE-2026-66034 7.5 Helios, morris, mufasa accepted_risk, not_applicable libssh → CVE-2026-66033
CVE-2026-66035 7.5 morris, mufasa not_applicable libssh → CVE-2026-66033

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Host OS / kernel

OS
Debian GNU/Linux 10 (buster) (10) · debian
Arch
x86_64
kernel_release
uname -r → 4.19.0-27-amd64
kernel_version
uname -v → #1 SMP Debian 4.19.316-1 (2024-06-25)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Description

A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.

Determination

libssh-gcrypt-40.8.7-1+deb10u2 : Vulnerable
libssh (related)0.8.7 series: Vulnerable
Practical Risk

Requires authenticated access to an SFTP service that uses libssh.
Not remotely exploitable by anonymous users.

Update status

Add note only

Mitigation log

2026-08-04T20:03:44Z — affects
libssh-gcrypt-40.8.7-1+deb10u2 : Vulnerable libssh (related)0.8.7 series: Vulnerable
2026-08-04T20:04:00Z — accepted_risk
Practical Risk Requires authenticated access to an SFTP service that uses libssh. Not remotely exploitable by anonymous users.

References

NVD: CVE-2025-5318