[CLSA-2025:1759330475] libssh: Fix of CVE-2025-5372
Type:
security
Severity:
Important
Release date:
2025-10-01 14:54:42 UTC
Description:
- CVE-2025-5372: uninitialized key buffers caused by inconsistent ssh_kdf() return value
Updated packages:
  • libssh-0.9.6-14.el8.tuxcare.els2.i686.rpm
    sha:5dcac0e4dc6616a846c6be32053d47afce6571e707b79b429d1ce8fa5e41caf2
  • libssh-0.9.6-14.el8.tuxcare.els2.x86_64.rpm
    sha:46f85e44ab6910fb9700ace33955c06c39d1809d938cd3b7f0a54a871d5fe922
  • libssh-config-0.9.6-14.el8.tuxcare.els2.noarch.rpm
    sha:8f8d256d82cab2227f43c03327ff5691b7250c5191115824f045c0025c472530
  • libssh-devel-0.9.6-14.el8.tuxcare.els2.i686.rpm
    sha:a58d5bcb9c93253bdc7d266e295ccd31d753a3d68aabb680b8b66cf5dfb85d16
  • libssh-devel-0.9.6-14.el8.tuxcare.els2.x86_64.rpm
    sha:6c98105646cf5244475ad18fef6eecc5f08d58022b0d4b3805528e2b2ee752ad
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.