gpp_maybe
Security update for libssh
SUSE-SLE-Micro-6.0-419
This update for libssh fixes the following issues: - CVE-2025-5372: ssh_kdf() returns a success code on certain failures (bsc#1245314) - CVE-2025-5987: Invalid return code for chacha20 poly1305 with OpenSSL backend (bsc#1245317) - CVE-2025-4877: Write beyond bounds in binary to base64 conversion functions (bsc#1245309) - CVE-2025-4878: Use of uninitialized variable in privatekey_from_file() (bsc#1245310) - CVE-2025-5318: Likely read beyond bounds in sftp server handle management (bsc#1245311) - CVE-2025-5351: Double free in functions exporting keys (bsc#1245312)
-
Release DateAug 14 2025
-
ReferencesBugzilla: 1245309, 1245310, 1245311, 1245312, 1245314, 1245317
CVEs: CVE-2025-4877, CVE-2025-4878, CVE-2025-5318, CVE-2025-5351, CVE-2025-5372, CVE-2025-5987 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Micro 6.0 aarch64
-
Packageslibssh-config
SSH library configuration fileslibssh40.10.6-2.1 lock rpm
SSH library0.10.6-2.1 lock rpm
SUSE Linux Micro 6.0 s390x
-
Packageslibssh-config
SSH library configuration fileslibssh40.10.6-2.1 lock rpm
SSH library0.10.6-2.1 lock rpm
SUSE Linux Micro 6.0 x86_64
-
Packageslibssh-config
SSH library configuration fileslibssh40.10.6-2.1 lock rpm
SSH library0.10.6-2.1 lock rpm