CVE-2025-8114: Libssh: null pointer dereference in libssh kex session id calculation

Published Jul 24, 2025
·
Updated

: null pointer dereference in libssh kex session id calculation

Other sources

A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.

NVD

NULL Pointer Dereference vulnerability in the session ID calculation logic of the libssh library. The flaw arises from improper handling of allocation errors during cryptographic operations in the key exchange (KEX) phase. If a memory allocation fails, the resulting NULL pointer may be dereferenced, leading to a crash in both SSH clients and servers. This vulnerability can be exploited by a local attacker with limited privileges and no user interaction, potentially disrupting services that rely on libssh for secure communication.The issue affects libssh versions up to and including 0.11.2.

Red Hat

Affected Software

9 affected componentsFixes available
libssh libssh<=0.11.2
libssh libssh<=0.11.2
Microsoft azl3 libssh 0.10.6-4
Microsoft cbl2 libssh 0.10.6-5
Microsoft azl3 libssh 0.10.6-2
Microsoft cbl2 libssh 0.10.6-3
Microsoft cbl2 libssh 0.10.6-2
Microsoft azl3 libssh 0.10.6-3
Microsoft azl3 libssh 0.10.6-5

Event History

Jul 24, 2025
Data Sourced
via Red Hat·12:41 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·02:14 PM
Data Sourced
via MITRE·02:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 3, 2025
Data Sourced
via Microsoft·11:24 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·11:24 PM
Affected Software
Updated
via Microsoft·11:24 PM
SeverityAffected Software
Updated
via Microsoft·11:24 PM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-8114?

CVE-2025-8114 is classified as a medium severity vulnerability due to potential client or server crashes.

2

How do I fix CVE-2025-8114?

To fix CVE-2025-8114, update libssh to version 0.11.3 or later where the vulnerability is addressed.

3

What types of systems are affected by CVE-2025-8114?

CVE-2025-8114 affects systems using libssh versions up to and including 0.11.2.

4

What is the impact of CVE-2025-8114?

The impact of CVE-2025-8114 includes potential crashes for both clients and servers during key exchange.

5

Is CVE-2025-8114 a remote code execution vulnerability?

No, CVE-2025-8114 is not a remote code execution vulnerability; it primarily causes crashes due to NULL pointer dereferencing.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203