CVE-2025-5351
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-5351 is a security vulnerability affecting libssh versions 0.10.0 and later when built with OpenSSL 3.0 or higher. The vulnerability was discovered and reported by Ronald Crane via Zippenhop LLC, and was publicly disclosed on June 24, 2025. This vulnerability involves a double free corruption that occurs in functions responsible for exporting keys (LibSSH Advisory).

Technical details

The vulnerability exists in the pkikeytoblob() function, which is used by various other functions for exporting public or private keys to blobs or base64. The issue occurs because the function fails to reset the 'params' variable to NULL after freeing it. Under low-memory conditions, when string allocation fails, libssh calls OSSLPARAM_free() with the same arguments, leading to a double free corruption. The vulnerability has been assigned a CVSS v3.1 score of 3.8 (AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C) (LibSSH Advisory).

Impact

The vulnerability can result in a system crash due to double free corruption when attempting to export keys under specific conditions. The impact is primarily limited to confidentiality and integrity with low severity, as indicated by the CVSS score. The vulnerability requires network access and high attack complexity to exploit (LibSSH Advisory).

Mitigation and workarounds

The vulnerability has been fixed in libssh version 0.11.2. System administrators are strongly advised to upgrade to this version as soon as possible. No workarounds are available for this vulnerability. Patches addressing the issue have been made available through the libssh security portal (LibSSH Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management