Threats Tagged 'cve-2025-5372'
View all threats tagged with 'cve-2025-5372'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-5372'
Click on any threat for detailed analysis and mitigation recommendations
0 libssh is a library which implements the SSH protocol. It can be used to implement client and server applications. Security Fix(es): * libssh: Incorrect Return Code Handling in ssh_kdf() in libssh (CVE-2025-5372) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 12/10/2025, 10:23:22 UTC Added: 05/26/2026, 20:58:38 UTC |
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability. Join the discussion | CVE Database V5 | 07/04/2025, 06:01:27 UTC Added: 07/04/2025, 06:09:29 UTC |
Showing 1 to 2 of 2 results