关键漏洞信息 漏洞概述 类型/严重性: 中等安全更新 主题: libssh的安全更新,适用于Red Hat Enterprise Linux 9。 描述 安全修复: - libssh: 在sftp_handle()中存在越界读取问题 (CVE-2025-5318) 影响的产品 Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x 修复措施 BZ - 2369131 - CVE-2025-5318 libssh: out-of-bounds read in sftp_handle() CVE编号 CVE-2025-5318 参考链接 https://access.redhat.com/security/updates/classification/#moderate