REDHAT-BUG-2506857: Medium severity libssh2 libssh2 vulnerability
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftpopen() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSHFXPOPEN with SSHFXPSTATUS containing FXOK, the response data buffer is freed, and if a subsequent sftppacketrequire() call returns a specific error such as LIBSSH2ERRORCHANNELPACKETEXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libssh2to a version that resolves this vulnerability.Fixed in 1.11.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 5e47761
Event History
Frequently Asked Questions
Which systems are realistically exposed to this issue?
Authenticated libssh2 clients that open an SFTP session to a malicious SSH server are exposed. The described heap-corruption impact is specifically associated with glibc systems, where tcache-dup conditions can lead to overlapping allocations and function-pointer overwrites.
What does an attacker need to do to trigger the vulnerable path?
The attacker needs to operate or control an SSH server that the client authenticates to and uses for SFTP. The server must return an SSH_FXP_STATUS response with FX_OK to an SSH_FXP_OPEN request and then cause a subsequent sftp_packet_require() call to return a relevant error, such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED.
How can I determine whether my libssh2 version needs remediation?
Versions of libssh2 through 1.11.1 are identified as affected. The issue is fixed in commit 5e47761.