• CVE-2025-5318

发布时间: 2025年7月4日

修改时间: 2025年7月11日

概要

A flaw was found in the libssh library. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.

CVSS v3 指标

NVD openEuler
Confidentiality High Low
Attack Vector Network Network
CVSS评分 8.1 5.4
Attack Complexity Low Low
Privileges Required Low Low
Scope Unchanged Unchanged
Integrity None Low
User Interaction None None
Availability High None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2741 libssh security update 2025年8月18日

影响产品

产品 状态
KY3.4-5 libssh Fixed
V6 libssh Fixed
KY3.5.3 libssh Fixed
KY3.5.2 libssh Fixed