Junglewise Threat Intelligence

CVE-2025-8277: libssh memory exhaustion via repeated key exchange guesses

CVE-2025-8277 · Severity: low · CVSS 3.1 · Published 2025-09-09

Technologies: Red Hat Enterprise Linux 9, Libssh. Vendors: Red Hat, Libssh.

Executive brief

libssh is a software library used by applications to provide secure communication via the SSH protocol. A flaw in how it handles security key updates allows an authenticated user to cause the application to consume excessive memory by repeatedly sending incorrect security guesses. This can eventually lead to the application crashing or becoming unresponsive, impacting service availability.

Technical details

A memory leak exists in libssh's key exchange (KEX) logic when the 'first_kex_packet_follows' flag is used in a KEXINIT message. When a client repeatedly provides incorrect KEX guesses during rekeying operations, the library fails to free previously allocated ephemeral key pairs in 'session->next_crypto' before allocating new ones. This flaw affects multiple KEX algorithms (Curve25519, ECDH, DH-GEX) across various crypto backends including OpenSSL, libgcrypt, and mbedTLS. While exploitation requires an authenticated client and does not affect the server side, it can lead to system memory exhaustion or crashes, particularly in environments using libgcrypt's fixed-size secure memory pool. The issue is resolved in libssh version 0.11.3.

Affected products

  • libssh libssh >= 0.6.0, < 0.11.3
  • Red Hat Enterprise Linux 9 libssh-0.10.4-18.el9

Timeline

  • 2025-07-28: other: Reported to Red Hat Bugzilla
  • 2025-09-09: disclosed: CVE published
  • 2026-05-06: advisory: libssh project advisory released
  • 2026-05-19: patched: Red Hat released patches for RHEL 9

References

Related threats