libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.
The product uses or accesses a resource that has not been initialized.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libssh2 | Libssh2 | * | 1.11.1 (including) |
| Libssh2 | Ubuntu | devel | * |
| Libssh2 | Ubuntu | noble | * |
| Libssh2 | Ubuntu | questing | * |
| Libssh2 | Ubuntu | resolute | * |