CVE-2025-4878

LOW

Red Hat Enterprise Linux 10 - Use-After-Free in privatekey_from_file()

Title source: llm
STIX 2.1

Description

A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.

Scores

CVSS v3 3.6
EPSS 0.0020
EPSS Percentile 41.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (7)
Red Hat/Red Hat Enterprise Linux 10
Red Hat/Red Hat Enterprise Linux 6
Red Hat/Red Hat Enterprise Linux 7
Red Hat/Red Hat Enterprise Linux 8
Red Hat/Red Hat Enterprise Linux 9
Red Hat/Red Hat Enterprise Linux 9 0:0.10.4-18.el9
Red Hat/Red Hat OpenShift Container Platform 4
Published Jul 22, 2025
Tracked Since Feb 18, 2026