Back

MEDIUM

libssh: authorization bypass in pki_verify_data_signature

Published May 26, 2023

Description

A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the return value `rc,` which is initialized to SSH_ERROR and later rewritten to save the return value of the function call `pki_key_check_hash_compatible.` The value of the variable is not changed between this point and the cryptographic verification. Therefore any error between them calls `goto error` returning SSH_OK.

Affected products

Remediation

No remediation recorded yet.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 26, 2023
Updated Nov 3, 2025
Reserved Apr 25, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 5, 2023
ENISA EUVD
Assigner redhat
Published May 26, 2023
Updated Nov 3, 2025
Exploited since n/a
EUVD-2023-33789