SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2025-5449

The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems.

MEDIUM 6.5EPSS 0.84%

Does this matter?

Lower severity and a low EPSS score (0.84%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads to failed memory allocation and causes the server process to crash, resulting in a denial of service.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.84% probability · 56th percentile
CISA KEV
Not listed
Weakness
CWE-190
Affected
libssh/libssh
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.