# CVE-2025-4878

## Summary

- **CVE ID:** CVE-2025-4878
- **Severity:** LOW
- **CVSS Score:** 3.6 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N)
- **CWE:** CWE-416
- **Published:** Jul 22, 2025
- **Last Modified:** Sep 1, 2026

## Description

A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.

## Affected Products

- Unknown product (0)
- Red Hat — Red Hat Enterprise Linux 9 (0:0.10.4-18.el9)

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2025-4878)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2376184)
- [CNA](https://git.libssh.org/projects/libssh.git/commit/?id=697650caa97eaf7623924c75f9fcfec6dd423cd1)
- [CNA](https://git.libssh.org/projects/libssh.git/commit/?id=b35ee876adc92a208d47194772e99f9c71e0bedb)
- [CNA](https://www.libssh.org/security/advisories/CVE-2025-4878.txt)
- [CNA](https://access.redhat.com/errata/RHSA-2026:18683)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 8.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._