Impact
A flaw in the libssh library allows an authenticated remote peer to advertise a zero maximum packet size during an SSH channel open request. The server subsequently enters an infinite loop when writing to that channel, consuming CPU resources until the process is terminated. This results in a denial of service that reduces the availability of the host system. The weakness maps to CWE‑400: Uncontrolled Resource Consumption.
Affected Systems
The vulnerability is present in Red Hat Enterprise Linux 10, 8, and 9, as well as Red Hat Hardened Images that ship the libssh component (Hummingbird). Any system running the affected package versions is impacted.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, and the EPSS score of less than 1% points to a low probability of exploitation in the wild. The attack path requires an authenticated SSH session, meaning the attacker must have valid credentials or have already compromised the target. No workaround is available, and the issue is not listed in CISA KEV, so the recommended response is to apply the vendor update promptly.
OpenCVE Enrichment
Debian DSA