A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed.
{
"binaries": [
{
"binary_name": "libssh-4",
"binary_version": "0.10.6-2ubuntu0.1"
},
{
"binary_name": "libssh-dev",
"binary_version": "0.10.6-2ubuntu0.1"
},
{
"binary_name": "libssh-gcrypt-4",
"binary_version": "0.10.6-2ubuntu0.1"
},
{
"binary_name": "libssh-gcrypt-dev",
"binary_version": "0.10.6-2ubuntu0.1"
}
],
"availability": "No subscription required"
}