[CLSA-2025:1759951300] libssh: Fix of CVE-2025-5372
Type:
security
Severity:
Important
Release date:
2025-10-08 19:21:51 UTC
Description:
- CVE-2025-5372: uninitialized key buffers caused by inconsistent ssh_kdf() return value
Updated packages:
  • libssh-0.9.4-3.el8.tuxcare.els6.i686.rpm
    sha:0d8fcfdb184d4a92d80ded09208ef84f7998606173a4ecb22ece3d81a10f88e4
  • libssh-0.9.4-3.el8.tuxcare.els6.x86_64.rpm
    sha:508caae42e291e83cfcf3a6a0ab198c8203806c53f682589a0da81da6e188e1f
  • libssh-config-0.9.4-3.el8.tuxcare.els6.noarch.rpm
    sha:9b719f0a24f7fc6a0fef5812da99a81979dd8ad35c19ea04168899b523740867
  • libssh-devel-0.9.4-3.el8.tuxcare.els6.i686.rpm
    sha:6c73a240f02e68e04dabf2036d6d5625b06aca86b43083dc458e18492ec24613
  • libssh-devel-0.9.4-3.el8.tuxcare.els6.x86_64.rpm
    sha:fedf8ba6b9a703d549ed9e6ac74c238ad04be62ab3cfaf414c9ad162c3d3f351
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.