CVE-2025-5318 Information
Jun 26, 2025
cve
Description
A flaw was found in the libssh library. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions exposing sensitive information or affect service behavior.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Reference
https://access.redhat.com/security/cve/CVE-2025-5318 https://bugzilla.redhat.com/show_bug.cgi?id=2369131 https://www.libssh.org/security/advisories/CVE-2025-5318.txt
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: