CVE-2025-15661

⚪ Do wiadomości

Błąd odczytu poza granicami w libssh2 umożliwia ujawnienie pamięci lub awarię aplikacji.

CVSS
6.5
EPSS
0.7%
Exploit
none
Vendor
libssh2
Opis źródłowy (NVD)

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.7%
Opublikowano (NVD)2026-06-18 21:16:27 UTC
Ostatnia modyfikacja (NVD)2026-10-05 16:10:00 UTC
Referencje