This update for libssh fixes the following issues:
CVE-2025-8277: memory exhaustion leading to client-side DoS due to improper memory management when KEX process is
repeated with incorrect guesses (bsc#1249375).
CVE-2025-8114: NULL pointer dereference when an allocation error happens during the calculation of the KEX session ID
(bsc#1246974).
Affected Packages
libssh-config
SUSE Linux Enterprise Micro 5.1SUSE Linux Enterprise Micro 5.2
Fixed in:
0.9.8-150200.13.12.1
libssh4
SUSE Linux Enterprise Micro 5.1SUSE Linux Enterprise Micro 5.2