A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.
0.6.3-3ubuntu30.6.3-4.10.6.3-4.20.6.3-4.2ubuntu10.6.3-4.30.6.3-4.3ubuntu0.10.6.3-4.3ubuntu0.20.6.3-4.3ubuntu0.50.6.3-4.3ubuntu0.60.6.3-4.3ubuntu0.6+esm10.7.5-10.8.0~20170825.94fa1e38-10.8.0~20170825.94fa1e38-1build10.8.0~20170825.94fa1e38-1ubuntu0.10.8.0~20170825.94fa1e38-1ubuntu0.20.8.0~20170825.94fa1e38-1ubuntu0.50.8.0~20170825.94fa1e38-1ubuntu0.60.8.0~20170825.94fa1e38-1ubuntu0.70.8.0~20170825.94fa1e38-1ubuntu0.7+esm30.9.0-1ubuntu10.9.0-1ubuntu40.9.0-1ubuntu50.9.3-2ubuntu10.9.3-2ubuntu20.9.3-2ubuntu2.10.9.3-2ubuntu2.20.9.3-2ubuntu2.30.9.3-2ubuntu2.40.9.3-2ubuntu2.50.9.6-10.9.6-1build10.9.6-20.9.6-2build10.9.6-2ubuntu0.22.04.10.9.6-2ubuntu0.22.04.20.9.6-2ubuntu0.22.04.30.9.6-2ubuntu0.22.04.40.10.6-2build20.10.6-30.10.6-3ubuntu10.10.6-3ubuntu1.10.10.5-3ubuntu10.10.5-3ubuntu20.10.6-20.10.6-2build10.10.6-2build20.10.6-2ubuntu0.10.10.6-3ubuntu10.11.1-10.11.1-1ubuntu0.10.6.3-3ubuntu30.6.3-4.10.6.3-4.20.6.3-4.2ubuntu10.6.3-4.30.6.3-4.3ubuntu0.10.6.3-4.3ubuntu0.20.6.3-4.3ubuntu0.50.6.3-4.3ubuntu0.60.6.3-4.3ubuntu0.6+esm10.7.5-10.8.0~20170825.94fa1e38-10.8.0~20170825.94fa1e38-1build10.8.0~20170825.94fa1e38-1ubuntu0.10.8.0~20170825.94fa1e38-1ubuntu0.20.8.0~20170825.94fa1e38-1ubuntu0.50.8.0~20170825.94fa1e38-1ubuntu0.60.8.0~20170825.94fa1e38-1ubuntu0.70.8.0~20170825.94fa1e38-1ubuntu0.7+esm30.9.0-1ubuntu10.9.0-1ubuntu40.9.0-1ubuntu50.9.3-2ubuntu10.9.3-2ubuntu20.9.3-2ubuntu2.10.9.3-2ubuntu2.20.9.3-2ubuntu2.30.9.3-2ubuntu2.40.9.3-2ubuntu2.5Exploitability
AV:NAC:HPR:LUI:NScope
S:UImpact
C:LI:LA:LCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L