Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2025-98

A flaw was found in the key export functionality of libssh

JLSEC Published
Modified
Affected Packages
libssh_jll < 0.11.3+0
Aliases / Upstream
CVE-2025-5351

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.

References