{"id":"CVE-2025-15661","title":"libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c","summary":"libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory cont…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","cvssSource":"cna","cwe":["CWE-125"],"vendor":"libssh2","product":"libssh2","affected":["libssh2 <= 1.11.1"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-06-22T18:07:05.411976Z"},"published":"2026-06-18","updated":"2026-09-24","sourceUpdated":"2026-09-24T14:17:17.482Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-15661","references":[{"url":"https://github.com/libssh2/libssh2/pull/1705","label":"Researcher Pull Request"},{"url":"https://github.com/libssh2/libssh2/pull/1717","label":"Maintainer Pull Request"},{"url":"https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d","label":"Patch Commit"},{"url":"https://www.vulncheck.com/advisories/libssh2-heap-buffer-over-read-via-sftp-symlink-in-sftp-c"}],"tags":["cve.org"],"epss":0.00648,"epssPercentile":0.49674,"ingestedAt":"2026-09-24T15:45:56.735Z","slug":"CVE-2025-15661","body":"## Overview\n\nlibssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.\n\n## Affected\n\n- `libssh2 <= 1.11.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}