A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
The product incorrectly checks a return value from a function, which prevents it from detecting errors or exceptional conditions.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libssh | Libssh | - (including) | - (including) |
| Hardened_images | Redhat | - (including) | - (including) |
| Enterprise_linux | Redhat | 8.0 (including) | 8.0 (including) |
| Enterprise_linux | Redhat | 9.0 (including) | 9.0 (including) |
| Enterprise_linux | Redhat | 10.0 (including) | 10.0 (including) |
| Red Hat Hardened Images | RedHat | libssh-main-0.12.1-4.hum1 | * |