Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2025-5372
Libssh: incorrect return code handling in ssh_kdf() in libssh
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .0047 38.2 —
AFFECTED
Product Versions Fixed
libssh unspecified —
Red Hat Enterprise Linux 8 unspecified 0:0.9.6-16.el8_10
Red Hat Enterprise Linux 8 unspecified 0:0.9.6-16.el8_10
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support unspecified 0:0.9.4-2.el8_4.2
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On unspecified 0:0.9.4-2.el8_4.2
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support unspecified 0:0.9.6-4.el8_6.2
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On unspecified 0:0.9.6-4.el8_6.2
Red Hat Enterprise Linux 8.8 Telecommunications Update Service unspecified 0:0.9.6-13.el8_8.2
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions unspecified 0:0.9.6-13.el8_8.2
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions unspecified 0:0.9.6-3.el9_0.2
+ 6 more
TIMELINE
May 30 Reserved by redhat
Jul 4 Published (CNA: redhat)
Aug 21 RESCORED — CVE-2025-5372 (libssh). CVSS 5 → 8.8 (NVD).
Description
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| May 30, 2025 | Reserved | Reserved by redhat |
| July 4, 2025 | Published | Published (CNA: redhat) |
| August 21, 2026 | RESCORED | RESCORED — CVE-2025-5372 (libssh). CVSS 5 → 8.8 (NVD). |
Affected
Affected products and packages — 16 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| libssh | libssh | — | — | — |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | 0:0.9.6-16.el8_10 |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | 0:0.9.6-16.el8_10 |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | — | — | 0:0.9.4-2.el8_4.2 |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | — | — | 0:0.9.4-2.el8_4.2 |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | — | — | 0:0.9.6-4.el8_6.2 |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | — | — | 0:0.9.6-4.el8_6.2 |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | — | — | 0:0.9.6-13.el8_8.2 |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | — | — | 0:0.9.6-13.el8_8.2 |
| Red Hat | Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | — | — | 0:0.9.6-3.el9_0.2 |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 6 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 7 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | — | — | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-5372 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.