CVE-2025-5449: Libssh: integer overflow in libssh sftp server packet length validation leading to denial of service

Published Jun 2, 2025
·
Updated

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads to failed memory allocation and causes the server process to crash, resulting in a denial of service.

Other sources

Integer Overflow vulnerability in the SFTP server implementation of libssh. The flaw exists in the sftpdecodechanneldatatopacket() function, where a crafted packet with a large payload size (e.g., 0x7ffffffc) bypasses a validity check due to integer overflow on 32-bit platforms. While this does not lead to direct memory corruption, the failure to allocate the excessively large buffer results in a self-induced denial of service (DoS). This issue can only be exploited by authenticated users with SFTP access and affects servers running on 32-bit systems.

Affected versions: libssh 0.11.0 and 0.11.1

Red Hat

Affected Software

3 affected components
libssh libssh>=0.11.0<=0.11.1
libssh libssh=0.11.0
libssh libssh=0.11.1

Event History

Jun 2, 2025
Data Sourced
via Red Hat·07:13 AM
DescriptionSeverityAffected Software
Jul 25, 2025
CVE Published
via MITRE·05:19 PM
Data Sourced
via MITRE·05:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-5449?

CVE-2025-5449 is considered to have a moderate severity due to the potential for integer overflow leading to memory allocation failure.

2

How do I fix CVE-2025-5449?

To fix CVE-2025-5449, update libssh to version 0.11.2 or later, which addresses the integer overflow issue.

3

Which versions of libssh are affected by CVE-2025-5449?

CVE-2025-5449 affects libssh versions 0.11.0 to 0.11.1 inclusive.

4

What are the potential consequences of CVE-2025-5449?

The consequences of CVE-2025-5449 include server crashes or denial of service due to failed memory allocation.

5

Is CVE-2025-5449 specific to certain systems?

Yes, CVE-2025-5449 is particularly problematic on 32-bit systems due to the integer overflow vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203