CVE-2025-5987 describes a high-severity vulnerability in libssh, specifically impacting its use of the ChaCha20 cipher with OpenSSL. An attacker can exploit a heap exhaustion scenario, causing libssh to utilize a partially initialized cipher context due to an aliasing error between OpenSSL and SSH_OK error codes. This critical flaw (CVSS 8.1) can lead to severe consequences, including compromised data confidentiality and integrity, or application crashes. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.10.0, < 0.11.2CPE matchmatch criteria | cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025Libssh: invalid return code for chacha20 poly1305 with openssl backend
Jul 8, 2025libssh: Invalid return code for chacha20 poly1305 with OpenSSL backend
Apr 26, 2025