Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfqf-mv4p-9j4r

Опубликовано: 04 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.2

Описание

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.

EPSS

Процентиль: 7%
0.0003
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-415

Связанные уязвимости

CVSS3: 4.2
ubuntu
около 1 месяца назад

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.

CVSS3: 4.2
redhat
около 1 месяца назад

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.

CVSS3: 4.2
nvd
около 1 месяца назад

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.

CVSS3: 4.2
msrc
18 дней назад

Описание отсутствует

CVSS3: 4.2
debian
около 1 месяца назад

A flaw was found in the key export functionality of libssh. The issue ...

EPSS

Процентиль: 7%
0.0003
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-415