Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c5f3-hwj2-xp5p

Опубликовано: 28 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.3
CVSS3: 6.5

Описание

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.

EPSS

Процентиль: 20%
0.0028
Низкий

8.3 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.

CVSS3: 6.5
redhat
около 1 месяца назад

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.

CVSS3: 6.5
nvd
около 1 месяца назад

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.

msrc
27 дней назад

libssh2 - Free of Uninitialized Pointer in publickey List Cleanup

CVSS3: 6.5
debian
около 1 месяца назад

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but ...

EPSS

Процентиль: 20%
0.0028
Низкий

8.3 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-908