Impact
The vulnerability is a heap read caused by copying a Curve25519 public key that is shorter than expected during server-side GSSAPI key exchange in libssh. The flaw allows a remote unauthenticated attacker to read a small portion of server memory, potentially exposing sensitive data. This weakness is categorized as CWE-125, out-of-bounds read.
Affected Systems
The issue affects Red Hat Enterprise Linux 8, 9, 10 and Red Hat Hardened Images, which ship the vulnerable version of libssh. The specific product is the libssh library embedded in these operating systems.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need network access to establish an SSH session and trigger the vulnerable GSSAPI key exchange; no local privileges are required.
OpenCVE Enrichment