CVE-2025-8277
A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when using libgcrypt, which impacts application stability and availability.
Scoring
- Severity
- LOW
- CVSS base score
- 3.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.40%
- CWE
- CWE-401
- Published
- 2025-09-09
- Last modified
- 2026-09-01
Affected products
- Red Hat Red Hat Enterprise Linux 9
Weakness type
Related vulnerabilities
- CVE-2026-3650 — Grassroots DICOM Missing release of memory after effective lifetime
- CVE-2025-61974 — BIG-IP SSL/TLS vulnerability
- CVE-2025-30658 — Junos OS: SRX Series: On devices with Anti-Virus enabled, malicious server responses will cause memory to leak ultimately causing forwarding to stop
- CVE-2025-21599 — Junos OS Evolved: Receipt of specifically malformed IPv6 packets causes kernel memory exhaustion leading to Denial of Service
- CVE-2025-21091 — BIG-IP SNMP vulnerability
- CVE-2025-14027 — Rockwell Automation Recommends Upgrading From 1756-RM2 XT To 1756-RM3 XT
- CVE-2024-39549 — Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak
- CVE-2024-20304 — Cisco IOS XR Software Packet Memory Exhaustion Vulnerability