Bug 2369131 (CVE-2025-5318)

Summary: CVE-2025-5318 libssh: out-of-bounds read in sftp_handle()
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: adudiak, axel.lin, kshier, omaciel, security-response-team, stcannon, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2374586, 2374587    
Bug Blocks:    
Deadline: 2025-06-24   

Description OSIDB Bzimport 2025-05-29 07:05:51 UTC
Out-of-Bounds Read vulnerability in the SFTP server implementation of libssh, specifically within the sftp_handle() function. The flaw is due to an incorrect boundary check that permits the function to access memory beyond the valid handle list. This leads to the return of an invalid pointer, which is subsequently used in further processing. Although the issue requires authenticated access to the server, it can be exploited by a remote attacker with valid credentials to potentially read unintended memory regions, which could expose sensitive information or affect service behavior.

Comment 1 Axel 2025-10-07 06:40:25 UTC
Hi,
This is fixed in libssh-0.11.3.
Can someone help to update the status? (e.g. Fixed In Version:)

Comment 2 errata-xmlrpc 2025-10-16 10:16:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:18231 https://access.redhat.com/errata/RHSA-2025:18231

Comment 3 errata-xmlrpc 2025-10-16 21:48:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:18275 https://access.redhat.com/errata/RHSA-2025:18275

Comment 4 errata-xmlrpc 2025-10-20 02:10:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:18286 https://access.redhat.com/errata/RHSA-2025:18286

Comment 7 errata-xmlrpc 2025-10-23 19:46:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:19012 https://access.redhat.com/errata/RHSA-2025:19012

Comment 8 errata-xmlrpc 2025-10-27 01:26:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:19098 https://access.redhat.com/errata/RHSA-2025:19098

Comment 9 errata-xmlrpc 2025-10-27 08:19:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:19101 https://access.redhat.com/errata/RHSA-2025:19101

Comment 11 errata-xmlrpc 2025-11-03 01:19:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:19400 https://access.redhat.com/errata/RHSA-2025:19400

Comment 12 errata-xmlrpc 2025-11-03 01:35:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2025:19401 https://access.redhat.com/errata/RHSA-2025:19401

Comment 13 errata-xmlrpc 2025-11-03 12:06:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:19470 https://access.redhat.com/errata/RHSA-2025:19470

Comment 14 errata-xmlrpc 2025-11-03 12:14:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:19472 https://access.redhat.com/errata/RHSA-2025:19472

Comment 15 errata-xmlrpc 2025-11-05 04:43:14 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.20

Via RHSA-2025:19295 https://access.redhat.com/errata/RHSA-2025:19295

Comment 16 errata-xmlrpc 2025-11-05 12:24:50 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.17

Via RHSA-2025:19313 https://access.redhat.com/errata/RHSA-2025:19313

Comment 17 errata-xmlrpc 2025-11-05 18:13:33 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.19

Via RHSA-2025:19300 https://access.redhat.com/errata/RHSA-2025:19300

Comment 18 errata-xmlrpc 2025-11-11 13:52:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:20943 https://access.redhat.com/errata/RHSA-2025:20943

Comment 19 errata-xmlrpc 2025-11-11 19:12:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:21013 https://access.redhat.com/errata/RHSA-2025:21013

Comment 20 errata-xmlrpc 2025-11-17 15:12:54 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.18

Via RHSA-2025:19864 https://access.redhat.com/errata/RHSA-2025:19864

Comment 21 errata-xmlrpc 2025-11-20 07:56:54 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2025:21329 https://access.redhat.com/errata/RHSA-2025:21329

Comment 22 errata-xmlrpc 2025-11-27 12:19:15 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.12

Via RHSA-2025:21829 https://access.redhat.com/errata/RHSA-2025:21829

Comment 23 errata-xmlrpc 2025-12-05 13:27:09 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.13

Via RHSA-2025:22275 https://access.redhat.com/errata/RHSA-2025:22275