The ssh library was designed to be used by programmers needing a working SSH
implementation by the mean of a library. The complete control of the client is
made by the programmer. With libssh, you can remotely execute programs, transfer
files, use a secure and transparent tunnel for your remote programs. With its
Secure FTP implementation, you can play with remote files easily, without
third-party programs others than libcrypto (from openssl).
Update Information:
New upstream release fixing the following security weaknesses (CVE-2025-8114, CVE-2025-8277)
* Tue Sep 9 2025 Jakub Jelen
[ 1 ] Bug #2383236 - Private bug
https://bugzilla.redhat.com/show_bug.cgi?id=2383236
[ 2 ] Bug #2394021 - libssh-0.11.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2394021
[ 3 ] Bug #2394047 - CVE-2025-8277 libssh: Memory Exhaustion via Repeated Key Exchange in libssh [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2394047
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-88ec28aaee' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.