Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-5351

Published: June 28, 2025Last modified: July 4, 2025

Description

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.

Severity score breakdown

ParameterValue
Base score4.2
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibsshFixed (0.11.2-r0)
StreamlibsshFixed (0.11.2-r0)

References

ON THIS PAGE