CVE-2025-8114

Source
https://cve.org/CVERecord?id=CVE-2025-8114
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8114.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-8114
Downstream
AZL (2)
BELL (1)
CGA (2)
CLSA (1)
DEBIAN (1)
JLSEC (1)
MINI (1)
OESA (1)
openSUSE (2)
RHSA (1)
RLSA (1)
ROOT (1)
SUSE (9)
UBUNTU (1)
Related
Published
2025-07-24T14:14:47Z
Modified
2026-09-03T03:30:15Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Libssh: null pointer dereference in libssh kex session id calculation
Details

A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-476"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8114.json"
}
References

Affected packages

Git / git.libssh.org/projects/libssh.git

Affected ranges

Type
GIT
Repo
https://git.libssh.org/projects/libssh.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
301d0e16dfa8a5cac1cff956b6880ca90eb82864
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.11.3"
        }
    ],
    "source":  "AFFECTED_FIELD"
}
Type
GIT
Repo
https://gitlab.com/libssh/libssh-mirror
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "last_affected":  "0.11.2"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

libssh-0.*
libssh-0.11.0
libssh-0.11.1
libssh-0.11.2
libssh-0.8.0
Other
release-0-3-0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8114.json"