CVE-2025-8277: Libssh: memory exhaustion via repeated key exchange in libssh

Published Jul 28, 2025
·
Updated

A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability.

Other sources

Libssh: memory exhaustion via repeated key exchange in libssh

Microsoft

Memory Exhaustion vulnerability in the key exchange logic of the libssh library. When an authenticated client repeatedly performs rekeying with incorrect firstkexpacketfollows guesses, libssh allocates new ephemeral key pairs without freeing old ones stored in session->nextcrypto. Over time, this results in a memory leak that can exhaust system memory and cause a client-side denial-of-service (DoS). This flaw affects several KEX algorithms (Curve25519, ECDH, sntrup761x25519, DH-GEX) across multiple crypto backends (libgcrypt, OpenSSL, mbedTLS). The issue requires an authenticated client and does not impact the server side. Versions Affected : libssh >= 0.6.0

Red Hat

Affected Software

7 affected componentsFixes available
libssh libssh
Microsoft azl3 libssh 0.10.6-3
Microsoft cbl2 libssh 0.10.6-2
Microsoft cbl2 libssh 0.10.6-3
Microsoft cbl2 libssh 0.10.6-5
Microsoft azl3 libssh 0.10.6-3
Microsoft azl3 libssh 0.10.6-4

Event History

Jul 28, 2025
Data Sourced
via Red Hat·11:06 AM
DescriptionSeverityAffected Software
Sep 9, 2025
CVE Published
via MITRE·11:55 AM
Data Sourced
via MITRE·11:55 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Sep 11, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:01 AM
Affected Software
Updated
via Microsoft·01:01 AM
Description
Updated
via Microsoft·01:01 AM
SeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-8277?

CVE-2025-8277 is considered a medium severity vulnerability due to its potential to exhaust system memory.

2

How do I fix CVE-2025-8277?

To fix CVE-2025-8277, update libssh to the latest version after the patch for this vulnerability is released.

3

What systems are affected by CVE-2025-8277?

CVE-2025-8277 affects all versions of the libssh library that utilize the key exchange (KEX) process.

4

What are the potential consequences of CVE-2025-8277?

The consequence of CVE-2025-8277 can include application crashes on the client side due to memory exhaustion.

5

Is there any workaround for CVE-2025-8277?

Currently, there is no known workaround for CVE-2025-8277 other than applying the upcoming patches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203