3.7 LOW
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): LOW
Libssh: missing checks for return values for digests
A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection.
References
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-6918 x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea…
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt
- RHSA-2024:2504 vendor-advisory x_refsource_REDHAT x_transferred
- RHSA-2024:3233 vendor-advisory x_refsource_REDHAT x_transferred
- https://access.redhat.com/security/cve/CVE-2023-6918 x_transferred x_refsource_REDHAT vdb-entry
- RHBZ#2254997 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://www.libssh.org/2023/12/18/libssh-0-10-6-and-libssh-0-9-8-security-relea… x_transferred
- https://www.libssh.org/security/advisories/CVE-2023-6918.txt x_transferred
- https://security.netapp.com/advisory/ntap-20250214-0009/
Affected products
- ==0.10.6
- ==0.9.8
- *
Matching in nixpkgs
pkgs.libssh2
Client-side C library implementing the SSH2 protocol
-
nixos-unstable -
- nixpkgs-unstable 1.11.1
pkgs.haskellPackages.libssh
libssh bindings
-
nixos-unstable -
- nixpkgs-unstable 0.1.0.0
pkgs.python312Packages.ansible-pylibssh
Python bindings to client functionality of libssh specific to Ansible use case
-
nixos-unstable -
- nixpkgs-unstable 1.2.2
pkgs.python313Packages.ansible-pylibssh
Python bindings to client functionality of libssh specific to Ansible use case
-
nixos-unstable -
- nixpkgs-unstable 1.2.2
pkgs.tests.pkg-config.defaultPkgConfigPackages.libssh2
Test whether libssh2-1.11.1 exposes pkg-config modules libssh2
-
nixos-unstable -
- nixpkgs-unstable libssh2
Package maintainers
-
@svanderburg Sander van der Burg <s.vanderburg@tudelft.nl>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@geluk Johan Geluk <johan+nix@geluk.io>