[CLSA-2025:1759857168] libssh: Fix of CVE-2025-5372
Type:
security
Severity:
Important
Release date:
2025-10-07 17:12:52 UTC
Description:
- CVE-2025-5372: uninitialized key buffers caused by inconsistent ssh_kdf() return value
Updated packages:
  • libssh-0.9.4-3.el8.tuxcare.els6.i686.rpm
    sha:e72c28b5063dba357437811104ac8fd472b90d5cf61cf45d6fd722bb5d53ee2b
  • libssh-0.9.4-3.el8.tuxcare.els6.x86_64.rpm
    sha:086abae76b3d234a8696fb7674cf0d9ccf55032cf20d744827dd4d0a838da779
  • libssh-config-0.9.4-3.el8.tuxcare.els6.noarch.rpm
    sha:80eda964a306e23c7ef9da5db5d41726b3db2db1a5d466e360d36f1234ed53ca
  • libssh-devel-0.9.4-3.el8.tuxcare.els6.i686.rpm
    sha:b4dded2402c8d75bf213f1729cc6bd1430e995bcd41913313e4ad8008893d6d7
  • libssh-devel-0.9.4-3.el8.tuxcare.els6.x86_64.rpm
    sha:1f1ad4d41b1c560f128c11ab9994a0c0d460aac08ce66e26fd0dbd5cffc4ce30
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.