CVE-2025-4878

Public on 2025-06-27
Modified on 2025-06-27
Description
The privatekey_from_file() uses an uninitialized variable under certain
conditions, such as if the file specified by the filename argument doesn't
exist. This causes the code to return an invalid private key.

This defect, in turn, might cause signing failure. The bug might also cause a
Use-After-Free or corrupt the heap.

Note that privatekey_from_file() is a deprecated function and shouldn't be used
anymore!
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
4.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 libssh Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L