Untriaged
Permalink
CVE-2023-6918
3.7 LOW
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): LOW
Libssh: missing checks for return values for digests
A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection.
References
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:3233 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry x_transferred
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
Affected products
libssh
- ==0.10.6
- ==0.9.8
- *
libssh2
mingw-libssh2
Matching in nixpkgs
pkgs.libssh2
Client-side C library implementing the SSH2 protocol
-
nixos-unstable -
- nixpkgs-unstable 1.11.1
pkgs.haskellPackages.libssh
libssh bindings
-
nixos-unstable -
- nixpkgs-unstable 0.1.0.0
pkgs.python312Packages.ansible-pylibssh
Python bindings to client functionality of libssh specific to Ansible use case
-
nixos-unstable -
- nixpkgs-unstable 1.2.2
pkgs.python313Packages.ansible-pylibssh
Python bindings to client functionality of libssh specific to Ansible use case
-
nixos-unstable -
- nixpkgs-unstable 1.2.2
pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2
Test whether libssh2-1.11.1 exposes pkg-config modules libssh2
-
nixos-unstable -
- nixpkgs-unstable libssh2
Package maintainers
-
@svanderburg Sander van der Burg <s.vanderburg@tudelft.nl>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@geluk Johan Geluk <johan+nix@geluk.io>