Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-6918

19
FAUCET Score

CVE-2023-6918 is a flaw in libssh's message digest operations, where unchecked return values could lead to crashes or the use of uninitialized memory in key derivation functions. This vulnerability affects various versions of Fedora and Red Hat Enterprise Linux. Rated as Medium severity (CVSS 5.3), it can be exploited remotely with low complexity, potentially causing denial of service. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.9.0, < 0.9.8CPE matchmatch criteria
cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
>= 0.10.0, < 0.10.6CPE matchmatch criteria
cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
38CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.7LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.41%
Probability of exploitation in next 30 days
EPSS Percentile
69.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0141 is in the 52nd percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

denopatch availablevia llm_extracted
View patch
keraspatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: cbl2 libssh 0.10.6-1 on CBL Mariner 2.0Fixed in: 0.10.6-1
microsoftpatch availablevia msrc
Product: azl3 libssh 0.10.6-1 on Azure Linux 3.0Fixed in: 0.10.6-1
microsoftpatch availablevia msrc
Product: azl3 libssh 0.10.5-2 on Azure Linux 3.0Fixed in: 0.10.6-1
microsoftpatch availablevia msrc
Product: 20073-17084Fixed in: 0.10.6-1
microsoftpatch availablevia msrc
Product: 18208-16823Fixed in: 0.10.6-1
microsoftpatch availablevia msrc
Product: 18214-17084Fixed in: 0.10.6-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libssh-0:0.9.6-14.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: libssh-0:0.10.4-13.el9
View patch
redhatvendor investigatingvia nvd_reference
View patch

Vendor Advisories (4)

denollm-deno-b67a3af2ce0be075CRITICAL

HP ThinPro 8.0 SP 9 Security Updates

Jun 17, 2024
kerasllm-keras-7d8c31fee70361dcCRITICAL

HP ThinPro 8.0 SP 9 Security Updates

Jun 17, 2024
redhatCVE-2023-6918Low

libssh: Missing checks for return values for digests

Dec 18, 2023
microsoft2023-Dec/CVE-2023-6918Low

Libssh: missing checks for return values for digests

Dec 12, 2023

References

lists.fedoraproject.org / archives/list/[email protected]/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM
lists.fedoraproject.org / archives/list/[email protected]/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB
security.netapp.com / advisory/ntap-20250214-0009
access.redhat.com / errata/RHSA-2024:2504
access.redhat.com / errata/RHSA-2024:3233
access.redhat.com / security/cve/CVE-2023-6918
Mailing ListVendor Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
libssh.org / 2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-releases
Release Notes
libssh.org / security/advisories/CVE-2023-6918.txt
Vendor Advisory