[CLSA-2025:1765825935] libssh: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2025-12-17 14:54:24 UTC
Description:
0.10.5.tuxcare.els2-r0: - CVE-2025-5372 fix ChaCha20 initialization failure leading to an invalid cipher state - CVE-2025-5987 fix ssh_kdf() error handling flaw that allowed uninitialized keys
Updated packages:
  • libssh-0.10.5.tuxcare.els2-rr0.apk
    sha:Q1JgIEmz+GYjA9rXy1n2KsoLJfLrs=
  • libssh-dev-0.10.5.tuxcare.els2-rr0.apk
    sha:Q1xz3xCSkL+mxwP2M8mQNDOjI8GuU=
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.