Advisories ยป MGASA-2026-0189

Updated libssh packages fix security vulnerabilities

Publication date: 10 Jun 2026
Modification date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-4877 , CVE-2025-4878 , CVE-2025-5318 , CVE-2025-5351 , CVE-2025-5372 , CVE-2025-5449 , CVE-2025-5987

Description

CVE-2025-4877  Write beyond bounds in binary to base64 conversion
functions
CVE-2025-4878  Use of uninitialized variable in privatekey_from_file()
CVE-2025-5318  Likely read beyond bounds in sftp server handle
management
CVE-2025-5351  Double free in functions exporting keys
CVE-2025-5372  ssh_kdf() returns a success code on certain failures
CVE-2025-5449  Likely read beyond bounds in sftp server message decoding
CVE-2025-5987  Invalid return code for chacha20 poly1305 with OpenSSL
backend
                

References

SRPMS

9/core