CyberRota Analysis
AI-GeneratedA vulnerability in libssh2 versions up to 1.11.1 allows a malicious SSH server to exploit a missing bounds check, leading to an arbitrary-length heap out-of-bounds read and potential heap allocator state corruption. This can result in the leakage of sensitive memory pointers and may compromise the integrity of the application by freeing uninitialized pointers. Organizations using libssh2 should prioritize patching this vulnerability to mitigate the risk of exploitation, especially those relying on SSH for secure communications.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.
Related CVEs
Other vulnerabilities affecting the same vendor(s)