DNA View

High Severity Vulnerability

This vulnerability has been rated as High severity. Immediate action is recommended.

CVE-2025-5987

High
Low Medium High Critical
8.1
CVSS Score
Published: Jul 07, 2025
Last Modified: Mar 20, 2026

Vulnerability Description

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
N
Attack Complexity
H
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
H
Integrity
H
Availability
H

Known Affected Software

9 configuration(s) from 1 vendor(s)

libssh
Version:
0.10.2
CPE:
cpe:2.3:a:libssh:libssh:0.10.2:*:*:*:*:*:*:*
libssh
Version:
0.11.0
CPE:
cpe:2.3:a:libssh:libssh:0.11.0:*:*:*:*:*:*:*
libssh
Version:
0.10.0
CPE:
cpe:2.3:a:libssh:libssh:0.10.0:*:*:*:*:*:*:*
libssh
Version:
0.10.1
CPE:
cpe:2.3:a:libssh:libssh:0.10.1:*:*:*:*:*:*:*
libssh
Version:
0.10.5
CPE:
cpe:2.3:a:libssh:libssh:0.10.5:*:*:*:*:*:*:*
libssh
Version:
0.11.1
CPE:
cpe:2.3:a:libssh:libssh:0.11.1:*:*:*:*:*:*:*
libssh
Version:
0.10.4
CPE:
cpe:2.3:a:libssh:libssh:0.10.4:*:*:*:*:*:*:*
libssh
Version:
0.10.6
CPE:
cpe:2.3:a:libssh:libssh:0.10.6:*:*:*:*:*:*:*
libssh
Version:
0.10.3
CPE:
cpe:2.3:a:libssh:libssh:0.10.3:*:*:*:*:*:*:*
This vulnerability affects 9 software configuration(s). Ensure you patch all affected systems.

Available Security Patches

5 patches available from vendors

View All Patches
Oracle

CPUAPR2026

Oracle Critical Patch Update Advisory - April 2026

Severity
Critical
Released
Apr 21, 2026
Restart Required
Security Update
Oracle

CPUJAN2026

Oracle Critical Patch Update Advisory - January 2026

Severity
Critical
Released
Jan 20, 2026
Restart Required
Security Update
Oracle

CPUOCT2025

Oracle Critical Patch Update Advisory - October 2025

Severity
Critical
Released
Oct 21, 2025
Restart Required
Security Update
Microsoft

2025-Jul-CVE-2025-5987

CVE-2025-5987: Libssh: invalid return code for chacha20 poly1305 with openssl backend

Severity
Unknown
Released
Sep 17, 2025
Security Update
SUSE

CVE-2025-5987

CVE-2025-5987

Severity
Unknown
Released
Jul 12, 2025
Security Update

Severity Details

8.1
out of 10.0
High

Weakness Type (CWE)

CWE-393

Return of Wrong Status Code

Description
A function or operation returns an incorrect return value or status code that does not indicate the true result of execution, causing the product to modify its behavior based on the incorrect result.
Typical Severity
Medium
Abstraction Level
Base

Key Information

Published Date
July 07, 2025