Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: libssh Moderate DoS NULL Pointer Fix CVE-2025-8114 2025:03369-1

suse
Calendar Grey September 26, 2025
Dist Suse Esm H88
Solutions addressing memory leaks and NULL reference problems within libssh for various SUSE variants, spanning from openSUSE to enterprise editions, are available.
* bsc#1246974 * bsc#1249375 Cross-References: * CVE-2025-8114

Summary

## This update for libssh fixes the following issues: * CVE-2025-8277: memory exhaustion leading to client-side DoS due to improper memory management when KEX process is repeated with incorrect guesses (bsc#1249375). * CVE-2025-8114: NULL pointer dereference when an allocation error happens during the calculation of the KEX session ID (bsc#1246974). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3369=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-3369=1 openSUSE-SLE-15.6-2025-3369=1 * Basesystem Module 15-SP6

References

* bsc#1246974

* bsc#1249375

Cross-

* CVE-2025-8114

* CVE-2025-8277

CVSS scores:

* CVE-2025-8114 ( SUSE ): 5.7

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-8114 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-8114 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-8114 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-8277 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

* CVE-2025-8277 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected Products:

* Basesystem Module 15-SP6

* Basesystem Module 15-SP7

* openSUSE Leap 15.6

* SUSE Linux Enterprise Desktop 15 SP6

* SUSE Linux Enterprise Desktop 15 SP7

* SUSE Linux Enterprise Real Time 15 SP6

Announcement ID: SUSE-SU-2025:03369-1
Release Date: 2025-09-26T10:54:53Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here