Processing sftp server read may cause null dereference
Published Jul 21, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.90%
Description
A missing allocation check in sftp server processing read requests may cause a NULL dereference on low-memory conditions. The malicious client can request up to 4GB SFTP reads, causing allocation of up to 4GB buffers, which was not being checked for failure. This will likely crash the authenticated user's sftp server connection (if implemented as forking as recommended). For thread-based servers, this might also cause DoS for legitimate users. Given this code is not in any released versions, no security releases have been issued.
Affected products
- Vendor n/a Product Libssh Defaultaffected
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| n/a | Libssh | affected |
|
No data.
Red Hat Enterprise Linux 7
libssh
Not affected
Red Hat Enterprise Linux 8
libssh
Not affected
Red Hat Enterprise Linux 9
libssh
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | libssh | Not affected | n/a |
| Red Hat Enterprise Linux 8 | libssh | Not affected | n/a |
| Red Hat Enterprise Linux 9 | libssh | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
The SFTP server implementation is based on callbacks so you can rewrite the sftp_channel_default_data_callback() to provide additional checks.
[1] https://gitlab.com/libssh/libssh-mirror/-/blob/master/examples/sample_sftpserver.c#L330
Red Hat mitigation
The SFTP server implementation is based on callbacks so you can rewrite the sftp_channel_default_data_callback() to provide additional checks. [1] https://gitlab.com/libssh/libssh-mirror/-/blob/master/examples/sample_sftpserver.c#L330
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 26, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.90% (0.00903) | 58.38th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.77% (0.00767) | 50.56th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.42% (0.00424) | 60.11th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.06% (0.00062) | 28.61th | v3 (v2023.03.01) |
| Jun 20, 2024 | 0.05% (0.00053) | 21.20th | v3 (v2023.03.01) |
| May 31, 2024 | 0.04% (0.00044) | 13.07th | v3 (v2023.03.01) |
| Aug 2, 2023 | 0.04% (0.00044) | 11.07th | v3 (v2023.03.01) |
| Jul 22, 2023 | 0.04% (0.00043) | 7.02th | v3 (v2023.03.01) |
References (4)
- https://access.redhat.com/security/cve/CVE-2023-3603 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2221791 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-3603
- https://www.cve.org/CVERecord?id=CVE-2023-3603
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-3603 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2221791 | issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-3603 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-3603 |
Change history (0)
No recorded changes yet.