CVE Vulnerabilities

CVE-2025-8114

NULL Pointer Dereference

Published: Jul 24, 2025 | Modified: Nov 17, 2025
CVSS 3.x
4.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
4.7 MODERATE
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key exchange (KEX) process, an allocation failure in cryptographic functions may lead to a NULL pointer dereference. This issue can cause the client or server to crash.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
LibsshLibssh*0.11.2 (including)
LibsshUbuntuesm-infra/bionic*
LibsshUbuntuesm-infra/focal*
LibsshUbuntuesm-infra/xenial*
LibsshUbuntujammy*
LibsshUbuntunoble*
LibsshUbuntuplucky*
LibsshUbuntuquesting*
LibsshUbuntuupstream*

Potential Mitigations

References