CVE-2025-5372
Last modified
CVE-2025-5372 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libssh | Libssh | < 0.11.2 |
| Redhat | Openshift Container Platform | 4.0 |
| Redhat | Enterprise Linux | 6.0 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux | 9.0 |
| Redhat | Enterprise Linux | 10.0 |
References
- https://access.redhat.com/security/cve/CVE-2025-5372Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2369388Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-5372?
How severe is CVE-2025-5372?
How do I fix CVE-2025-5372?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-53714A vulnerability has been found in TP-Link TL-WR841N V11. The…7.5
- CVE-2025-53715A vulnerability has been found in TP-Link TL-WR841N V11. The…7.5
- CVE-2025-53716Null pointer dereference in Windows Local Security Authority…6.5
- CVE-2025-53717Reliance on untrusted inputs in a security decision in Windo…7
- CVE-2025-53718Use after free in Windows Ancillary Function Driver for WinS…7
- CVE-2025-53719Use of uninitialized resource in Windows Routing and Remote …5.7
- CVE-2025-53720Heap-based buffer overflow in Windows Routing and Remote Acc…8
- CVE-2025-53721Use after free in Windows Connected Devices Platform Service…7
- CVE-2025-53722Uncontrolled resource consumption in Windows Remote Desktop …7.5
- CVE-2025-53723Numeric truncation error in Windows Hyper-V allows an author…7.8
- CVE-2025-53724Access of resource using incompatible type ('type confusion'…7.8
- CVE-2025-53725Access of resource using incompatible type ('type confusion'…7.8
Are you affected by CVE-2025-5372?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
