Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 41: Fix for Critical Memory Leak and Pointer Issue in libssh

fedora
Calendar Grey September 24, 2025
Dist Fedora Esm H88
Fedora 41 libtls update resolves significant vulnerabilities such as buffer overflows and dangling pointers. Maintain your security!
New upstream release fixing the following security weaknesses (CVE-2025-8114, CVE-2025-8277)

Summary

The ssh library was designed to be used by programmers needing a working SSH

implementation by the mean of a library. The complete control of the client is

made by the programmer. With libssh, you can remotely execute programs, transfer

files, use a secure and transparent tunnel for your remote programs. With its

Secure FTP implementation, you can play with remote files easily, without

third-party programs others than libcrypto (from openssl).

Update Information:

New upstream release fixing the following security weaknesses (CVE-2025-8114, CVE-2025-8277)

Change Log

* Tue Sep 9 2025 Jakub Jelen - 0.11.3-1 - New upstream release fixing the following security weaknesses: - CVE-2025-8114: Fix NULL pointer dereference after allocation failure - CVE-2025-8277: Fix memory leak of ephemeral key pair during repeated wrong KEX * Thu Jul 24 2025 Fedora Release Engineering - 0.11.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild

References


[ 1 ] Bug #2383236 - Private bug https://bugzilla.redhat.com/show_bug.cgi?id=2383236 [ 2 ] Bug #2394021 - libssh-0.11.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2394021 [ 3 ] Bug #2394047 - CVE-2025-8277 libssh: Memory Exhaustion via Repeated Key Exchange in libssh [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2394047

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-88ec28aaee' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libssh
Product: Fedora 41
Version: 0.11.3
Release: 1.fc41
Summary: A library implementing the SSH protocol

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here