CVE-2025-5449

MEDIUM

libssh - Denial of Service via Integer Overflow in SFTP Server Message Decoding

Title source: llm
STIX 2.1

Description

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads to failed memory allocation and causes the server process to crash, resulting in a denial of service.

Scores

CVSS v3 6.5
EPSS 0.0074
EPSS Percentile 49.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (2)
libssh/libssh 0.11.0
libssh/libssh 0.11.1
Published Jul 25, 2025
Tracked Since Feb 18, 2026