This issue affects only 32-bits builds of libssh.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4385-1 | libssh security update |
EUVD |
EUVD-2025-28257 | There's a vulnerability in the libssh package where when a libssh consumer passes in an unexpectedly large input buffer to ssh_get_fingerprint_hash() function. In such cases the bin_to_base64() function can experience an integer overflow leading to a memory under allocation, when that happens it's possible that the program perform out of bounds write leading to a heap corruption. This issue affects only 32-bits builds of libssh. |
Ubuntu USN |
USN-7619-1 | libssh vulnerabilities |
Ubuntu USN |
USN-7696-1 | libssh vulnerabilities |
Wed, 20 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | There's a vulnerability in the libssh package where when a libssh consumer passes in an unexpectedly large input buffer to ssh_get_fingerprint_hash() function. In such cases the bin_to_base64() function can experience an integer overflow leading to a memory under allocation, when that happens it's possible that the program perform out of bounds write leading to a heap corruption. This issue affects only 32-bits builds of libssh. |
| Title | libssh: Write beyond bounds in binary to base64 conversion functions | Libssh: write beyond bounds in binary to base64 conversion functions |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| CPEs | cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| References |
|
Fri, 04 Jul 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | libssh: Write beyond bounds in binary to base64 conversion functions | |
| Weaknesses | CWE-190 CWE-787 |
|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-02-25T20:31:09.066Z
Reserved: 2025-05-16T22:23:41.045Z
Link: CVE-2025-4877
Updated: 2025-08-20T15:14:34.584Z
Status : Deferred
Published: 2025-08-20T13:15:28.890
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-4877
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN