CVE-2025-5372: Libssh: incorrect return code handling in ssh_kdf() in libssh

Published May 30, 2025
·
Updated

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the sshkdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.

Other sources

Incorrect Success Return vulnerability in the sshkdf() function of libssh when built with OpenSSL versions prior to 3.0. This issue arises because libssh interprets OpenSSL's return value 0 (indicating failure) as SSHOK (indicating success). As a result, on failure, the function may return success without initializing the output key buffers. This can lead to the use of uninitialized cryptographic keys, affecting the encryption and decryption of SSH traffic. The vulnerability allows an attacker to exploit improper key handling, potentially resulting in data leakage, integrity issues, or denial of service during SSH communication.

Red Hat

Libssh: incorrect return code handling in sshkdf() in libssh

Microsoft

Affected Software

16 affected componentsFixes available
libssh libssh>0
OpenSSL OpenSSL<3.0
Microsoft cbl2 libssh 0.10.6-1
Microsoft azl3 libssh 0.10.6-1
Microsoft cbl2 libssh 0.10.6-1
Microsoft cbl2 libssh 0.10.6-2
Microsoft azl3 libssh 0.10.6-2
libssh libssh<0.11.2
redhat OpenShift Container Platform=4.0
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0
IBM DS8A00( R10.0 - R10.1 )<=10.1.3.0 - 10.11.35.0
IBM DS8900F ( R9.4)<=89.40.83.0-89.44.25.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    In the ssh_kdf() function, do not interpret OpenSSL’s return value 0 (failure) as SSH_OK; adjust the return-code handling so key derivation failures do not proceed with uninitialized output key buffers.

    libssh ssh_kdf() return-code handling = Treat OpenSSL return value 0 as failure (not success)

Event History

May 30, 2025
Data Sourced
via Red Hat·11:36 AM
DescriptionSeverityAffected Software
Jul 4, 2025
CVE Published
via MITRE·06:01 AM
Data Sourced
via MITRE·06:01 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Jul 17, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Aug 19, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2025-5372?

CVE-2025-5372 has been assigned a severity rating that indicates a medium level of risk due to potential key derivation errors.

2

How do I fix CVE-2025-5372?

To fix CVE-2025-5372, upgrade libssh to a version that is compatible with OpenSSL 3.0 or newer.

3

What software is affected by CVE-2025-5372?

CVE-2025-5372 affects libssh versions built with OpenSSL versions older than 3.0.

4

What is the impact of CVE-2025-5372?

The impact of CVE-2025-5372 includes the potential for incorrect key derivation, which can lead to security vulnerabilities.

5

How can I determine if I'm using a vulnerable version related to CVE-2025-5372?

You can determine if you are vulnerable by checking the versions of both libssh and OpenSSL in your environment.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203