CyberRota Analysis
AI-GeneratedA flaw in libssh allows a remote authenticated peer to advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, which can result in an infinite loop during subsequent channel writes, ultimately consuming CPU resources and leading to a denial of service. Organizations using libssh should prioritize this vulnerability to mitigate potential service disruptions. This is particularly relevant for environments where SSH is heavily utilized for remote access and management.
Original NVD Description
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
Related CVEs
Other vulnerabilities affecting the same vendor(s)