CVE-2025-8114

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
24/07/2025
Last modified:
17/11/2025

Description

A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* 0.11.2 (including)