Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mf77-5hj2-98w9

Опубликовано: 28 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.3
CVSS3: 7

Описание

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

EPSS

Процентиль: 29%
0.00361
Низкий

8.3 High

CVSS4

7 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7
ubuntu
около 1 месяца назад

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

CVSS3: 7
redhat
около 1 месяца назад

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

CVSS3: 7
nvd
около 1 месяца назад

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.

msrc
около 1 месяца назад

libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation

CVSS3: 7
debian
около 1 месяца назад

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...

EPSS

Процентиль: 29%
0.00361
Низкий

8.3 High

CVSS4

7 High

CVSS3

Дефекты

CWE-190