https://seclists.org/oss-sec/2025/q3/138: libssh2 Base64 Encoding Heap Overflow in Known Hosts SHA1 Hash Processing
Published Aug 26, 2025
·Updated
Affected Software
1 affected component
libssh2 libssh2
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
The severity of CVE-2025-XXXX is categorized as high due to the potential for a heap overflow that can lead to remote code execution.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, update to the latest version of libssh2 where the vulnerability has been patched.
3
What systems are affected by CVE-2025-XXXX?
CVE-2025-XXXX affects all versions of libssh2 prior to the fixed release that addresses the Base64 encoding heap overflow.
4
What is the main vulnerability of CVE-2025-XXXX?
The main vulnerability of CVE-2025-XXXX is a heap overflow during the processing of SHA1 hashes in known hosts files.
5
How can CVE-2025-XXXX be exploited?
CVE-2025-XXXX can be exploited by an attacker providing malicious SSH known_hosts files leading to potential system compromise.