Описание
Security update for libssh
This update for libssh fixes the following issues:
- CVE-2025-8114: Fixed a NULL pointer dereference when calculating session ID during KEX. (bsc#1246974)
Список пакетов
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libssh-devel-doc-0.6.3-12.21.1
Ссылки
- Link for SUSE-SU-2025:4408-1
- E-Mail link for SUSE-SU-2025:4408-1
- SUSE Security Ratings
- SUSE Bug 1246974
- SUSE CVE CVE-2025-8114 page
Описание
A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.
Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libssh-devel-doc-0.6.3-12.21.1
Ссылки
- CVE-2025-8114
- SUSE Bug 1246974