Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-5318

27
FAUCET Score

CVE-2025-5318 identifies an out-of-bounds read vulnerability

Impacted Technologies

VendorProductVersion(s)CPE
4.0CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
< 0.11.2CPE matchmatch criteria
cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.45%
Probability of exploitation in next 30 days
EPSS Percentile
82.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0245 is in the 81st percentile among its peer group of 17,822 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (48)

autodeskpatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: 20179-17086Fixed in: 0.10.6-2
microsoftpatch availablevia msrc
Product: 18208-17086Fixed in: 0.10.6-2
microsoftpatch availablevia msrc
Product: cbl2 libssh 0.10.6-2 on CBL Mariner 2.0Fixed in: 0.10.6-2
microsoftpatch availablevia msrc
Product: azl3 libssh 0.10.6-2 on Azure Linux 3.0Fixed in: 0.10.6-2
microsoftpatch availablevia msrc
Product: azl3 libssh 0.10.6-1 on Azure Linux 3.0Fixed in: 0.10.6-2
microsoftpatch availablevia msrc
Product: 19623-17084Fixed in: 0.10.6-2
microsoftpatch availablevia msrc
Product: cbl2 libssh 0.10.6-1 on CBL Mariner 2.0Fixed in: 0.10.6-2
microsoftpatch availablevia msrc
Product: 18214-17084Fixed in: 0.10.6-2
microsoftpatch availablevia msrc
Product: 19574-16823Fixed in: 0.10.6-2
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: libssh-0:0.10.4-15.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: libssh-0:0.10.4-15.el9_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: libssh-0:0.9.6-3.el9_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: libssh-0:0.10.4-9.el9_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: libssh-0:0.10.4-13.el9_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.12Fixed in: rhcos-412.86.202511191939-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: rhcos-413.92.202511261311-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: rhcos-414.92.202511122212-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: rhcos-415.92.202601271320-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: rhcos-416.94.202601071926-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: rhcos-417.94.202510282022-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: rhcos-418.94.202511041748-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.19Fixed in: rhcos-4.19.9.6.202510281054-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.20Fixed in: rhcos-4.20.9.6.202510290321-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-cuda-rhel9:sha256:bddcf7ab6d576572b6d60822c313ffebcd9869e4fde93e32ac327821f93cf32b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/model-opt-cuda-rhel9:sha256:dce6b0ea03379bf06664a5200af8b5f5ae3fad13cdce6d21873843f22554800b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-cuda-rhel9:sha256:fa844e16d06e871f1a5dbc2fd5b3882d28112eee8d6bee601d94c96295c5e24f
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-rocm-rhel9:sha256:53007894763e03f609c35c727cb738db3c2130b19fa0e1069c24240e0870fb7a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.7.1Fixed in: rhosdt/tempo-gateway-opa-rhel8:sha256:3f12344a5c4c07de6355c07a70115b852a80559daf0c95aec586af96821b6b22
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.7.1Fixed in: rhosdt/tempo-gateway-rhel8:sha256:f242d27114fa7546df4d7261cccbd8586e9e6ba2487f02e260d8880807b94f43
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.7.1Fixed in: rhosdt/tempo-jaeger-query-rhel8:sha256:f0290670fda619de4bfa43aa13a720d227761308637320743a27e142dceedfce
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.7.1Fixed in: rhosdt/tempo-query-rhel8:sha256:d25818f8e291203973fee6941883297d32f24290701b5a0d218cfec56e824eea
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.7.1Fixed in: rhosdt/tempo-rhel8:sha256:0fbed65da8c168be024b4ec28e9c5a860ce81c5bee69ebea24002407dc002be8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.7.1Fixed in: rhosdt/tempo-rhel8-operator:sha256:054f4ed9b24b1bc6fc885408d261d74fd2fc9f97ed8fc62f4a167e08d2a18eb3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-rocm-rhel9:sha256:7856bdb7ae0d643a7b9362c164d4d4fe3c0c7186f5fff73a7ae9835b3df52e57
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: libssh-0:0.11.1-4.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: libssh-0:0.11.1-4.el10_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libssh-0:0.9.6-15.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: libssh-0:0.9.0-4.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: libssh-0:0.9.4-2.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: libssh-0:0.9.4-2.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: libssh-0:0.9.6-4.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: libssh-0:0.9.6-4.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: libssh-0:0.9.6-4.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: libssh-0:0.9.6-13.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: libssh-0:0.9.6-13.el8_8.1
View patch

Vendor Advisories (5)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
redhatCVE-2025-5318Moderate

libssh: out-of-bounds read in sftp_handle()

Jun 24, 2025
microsoft2025-Jun/CVE-2025-5318Moderate

Libssh: out-of-bounds read in sftp_handle()

Jun 10, 2025

References

access.redhat.com / errata/RHSA-2025:18231
Third Party Advisory
access.redhat.com / errata/RHSA-2025:18275
Third Party Advisory
access.redhat.com / errata/RHSA-2025:18286
Third Party Advisory
access.redhat.com / errata/RHSA-2025:19012
Third Party Advisory
access.redhat.com / errata/RHSA-2025:19098
Third Party Advisory
access.redhat.com / errata/RHSA-2025:19101
Third Party Advisory
access.redhat.com / errata/RHSA-2025:19295
access.redhat.com / errata/RHSA-2025:19300
access.redhat.com / errata/RHSA-2025:19313
access.redhat.com / errata/RHSA-2025:19400
access.redhat.com / errata/RHSA-2025:19401
access.redhat.com / errata/RHSA-2025:19470
access.redhat.com / errata/RHSA-2025:19472
access.redhat.com / errata/RHSA-2025:19807
access.redhat.com / errata/RHSA-2025:19864
access.redhat.com / errata/RHSA-2025:20943
access.redhat.com / errata/RHSA-2025:21013
access.redhat.com / errata/RHSA-2025:21329
access.redhat.com / errata/RHSA-2025:21829
access.redhat.com / errata/RHSA-2025:22275
access.redhat.com / errata/RHSA-2025:23078
access.redhat.com / errata/RHSA-2025:23079
access.redhat.com / errata/RHSA-2025:23080
access.redhat.com / errata/RHSA-2026:0326
access.redhat.com / errata/RHSA-2026:1541
access.redhat.com / errata/RHSA-2026:3461
access.redhat.com / errata/RHSA-2026:3462
access.redhat.com / security/cve/CVE-2025-5318
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
libssh.org / security/advisories/CVE-2025-5318.txt
Vendor Advisory