CVE-2025-4878: Use After Free
A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.
AI Analysis
Technical Summary
This vulnerability in libssh arises from the use of an uninitialized variable in the privatekey_from_file() function when the specified file is missing. This can lead to potential signing failures or heap corruption. The issue is documented under CVE-2025-4878 with a CVSS v3.1 base score of 3.6 (low severity). Red Hat has released security updates for libssh in Red Hat Enterprise Linux 9 that address this and other related vulnerabilities. The vendor advisory confirms the availability of patches and provides detailed remediation instructions.
Potential Impact
The vulnerability may cause signing failures or heap corruption when libssh attempts to process a non-existent file in the privatekey_from_file() function. This could affect applications relying on libssh for SSH key handling, potentially leading to application instability or failure in cryptographic operations. The CVSS score indicates limited confidentiality and integrity impact with no availability impact. There are no known exploits in the wild.
Mitigation Recommendations
Red Hat has released security updates that fix this vulnerability as part of libssh package updates for Red Hat Enterprise Linux 9. Users should apply the official patches provided in Red Hat Security Advisory RHSA-2026:18683. Refer to the vendor advisory at https://access.redhat.com/security/cve/CVE-2025-4878 and https://access.redhat.com/articles/11258 for detailed update instructions. No additional mitigation is required beyond applying the vendor-provided fix.
CVE-2025-4878: Use After Free
Description
A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.
CVSS v3.1
Score 3.6low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in libssh arises from the use of an uninitialized variable in the privatekey_from_file() function when the specified file is missing. This can lead to potential signing failures or heap corruption. The issue is documented under CVE-2025-4878 with a CVSS v3.1 base score of 3.6 (low severity). Red Hat has released security updates for libssh in Red Hat Enterprise Linux 9 that address this and other related vulnerabilities. The vendor advisory confirms the availability of patches and provides detailed remediation instructions.
Potential Impact
The vulnerability may cause signing failures or heap corruption when libssh attempts to process a non-existent file in the privatekey_from_file() function. This could affect applications relying on libssh for SSH key handling, potentially leading to application instability or failure in cryptographic operations. The CVSS score indicates limited confidentiality and integrity impact with no availability impact. There are no known exploits in the wild.
Mitigation Recommendations
Red Hat has released security updates that fix this vulnerability as part of libssh package updates for Red Hat Enterprise Linux 9. Users should apply the official patches provided in Red Hat Security Advisory RHSA-2026:18683. Refer to the vendor advisory at https://access.redhat.com/security/cve/CVE-2025-4878 and https://access.redhat.com/articles/11258 for detailed update instructions. No additional mitigation is required beyond applying the vendor-provided fix.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- redhat
- Date Reserved
- 2025-05-16T22:28:46.782Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2025-4878","vendor":"Red Hat"}]
Threat ID: 687fa0aca83201eaac1ccc8a
Added to database: 07/22/2025, 14:31:08 UTC
Last enriched: 07/02/2026, 21:57:19 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 193
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.