A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "0.10.6-2ubuntu0.1", "binary_name": "libssh-4" }, { "binary_version": "0.10.6-2ubuntu0.1", "binary_name": "libssh-4-dbgsym" }, { "binary_version": "0.10.6-2ubuntu0.1", "binary_name": "libssh-dev" }, { "binary_version": "0.10.6-2ubuntu0.1", "binary_name": "libssh-doc" }, { "binary_version": "0.10.6-2ubuntu0.1", "binary_name": "libssh-gcrypt-4" }, { "binary_version": "0.10.6-2ubuntu0.1", "binary_name": "libssh-gcrypt-4-dbgsym" }, { "binary_version": "0.10.6-2ubuntu0.1", "binary_name": "libssh-gcrypt-dev" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "0.11.1-1ubuntu0.1", "binary_name": "libssh-4" }, { "binary_version": "0.11.1-1ubuntu0.1", "binary_name": "libssh-4-dbgsym" }, { "binary_version": "0.11.1-1ubuntu0.1", "binary_name": "libssh-dev" }, { "binary_version": "0.11.1-1ubuntu0.1", "binary_name": "libssh-doc" } ] }