{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian11els/vex/2025/cve-2025-15661-els_os-debian11els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-09T08:42:34Z",
      "generator": {
        "date": "2026-09-09T08:42:34Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-15661-ELS_OS-DEBIAN11ELS",
      "initial_release_date": "2025-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2025-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-09T08:42:34Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2025-15661"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-1-dev-0:1.9.0-2+deb11u1.amd64",
                "product": {
                  "name": "libssh2-1-dev-0:1.9.0-2+deb11u1.amd64",
                  "product_id": "libssh2-1-dev-0:1.9.0-2+deb11u1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/libssh2-1-dev@1.9.0-2%2Bdeb11u1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-1-0:1.9.0-2+deb11u1.amd64",
                "product": {
                  "name": "libssh2-1-0:1.9.0-2+deb11u1.amd64",
                  "product_id": "libssh2-1-0:1.9.0-2+deb11u1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/libssh2-1@1.9.0-2%2Bdeb11u1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-1-dev-0:1.9.0-2+deb11u1.arm64",
                "product": {
                  "name": "libssh2-1-dev-0:1.9.0-2+deb11u1.arm64",
                  "product_id": "libssh2-1-dev-0:1.9.0-2+deb11u1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/libssh2-1-dev@1.9.0-2%2Bdeb11u1?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-1-0:1.9.0-2+deb11u1.arm64",
                "product": {
                  "name": "libssh2-1-0:1.9.0-2+deb11u1.arm64",
                  "product_id": "libssh2-1-0:1.9.0-2+deb11u1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/libssh2-1@1.9.0-2%2Bdeb11u1?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-1-dev-0:1.9.0-2+deb11u1.armel",
                "product": {
                  "name": "libssh2-1-dev-0:1.9.0-2+deb11u1.armel",
                  "product_id": "libssh2-1-dev-0:1.9.0-2+deb11u1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/libssh2-1-dev@1.9.0-2%2Bdeb11u1?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-1-0:1.9.0-2+deb11u1.armel",
                "product": {
                  "name": "libssh2-1-0:1.9.0-2+deb11u1.armel",
                  "product_id": "libssh2-1-0:1.9.0-2+deb11u1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/debian/libssh2-1@1.9.0-2%2Bdeb11u1?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
                "product": {
                  "name": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
                  "product_id": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssh2-1-dev@1.9.0-2%2Bdeb11u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
                "product": {
                  "name": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
                  "product_id": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssh2-1@1.9.0-2%2Bdeb11u1%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
                "product": {
                  "name": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
                  "product_id": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssh2-1-dev@1.9.0-2%2Bdeb11u1%2Btuxcare.els1?arch=arm64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
                "product": {
                  "name": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
                  "product_id": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssh2-1@1.9.0-2%2Bdeb11u1%2Btuxcare.els1?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
                "product": {
                  "name": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
                  "product_id": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssh2-1-dev@1.9.0-2%2Bdeb11u1%2Btuxcare.els1?arch=armel"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
                "product": {
                  "name": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
                  "product_id": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/libssh2-1@1.9.0-2%2Bdeb11u1%2Btuxcare.els1?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.amd64"
        },
        "product_reference": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-dev-0:1.9.0-2+deb11u1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1.amd64"
        },
        "product_reference": "libssh2-1-dev-0:1.9.0-2+deb11u1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.arm64"
        },
        "product_reference": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-dev-0:1.9.0-2+deb11u1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1.arm64"
        },
        "product_reference": "libssh2-1-dev-0:1.9.0-2+deb11u1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.armel as a component of Debian 11",
          "product_id": "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.armel"
        },
        "product_reference": "libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-dev-0:1.9.0-2+deb11u1.armel as a component of Debian 11",
          "product_id": "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1.armel"
        },
        "product_reference": "libssh2-1-dev-0:1.9.0-2+deb11u1.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.arm64"
        },
        "product_reference": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-0:1.9.0-2+deb11u1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:libssh2-1-0:1.9.0-2+deb11u1.arm64"
        },
        "product_reference": "libssh2-1-0:1.9.0-2+deb11u1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.amd64"
        },
        "product_reference": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-0:1.9.0-2+deb11u1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:libssh2-1-0:1.9.0-2+deb11u1.amd64"
        },
        "product_reference": "libssh2-1-0:1.9.0-2+deb11u1.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.armel as a component of Debian 11",
          "product_id": "Debian-11:libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.armel"
        },
        "product_reference": "libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libssh2-1-0:1.9.0-2+deb11u1.armel as a component of Debian 11",
          "product_id": "Debian-11:libssh2-1-0:1.9.0-2+deb11u1.armel"
        },
        "product_reference": "libssh2-1-0:1.9.0-2+deb11u1.armel",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-15661",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "description",
          "text": "libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Debian-11:libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
          "Debian-11:libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
          "Debian-11:libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
          "Debian-11:libssh2-1-0:1.9.0-2+deb11u1.amd64",
          "Debian-11:libssh2-1-0:1.9.0-2+deb11u1.arm64",
          "Debian-11:libssh2-1-0:1.9.0-2+deb11u1.armel",
          "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
          "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
          "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
          "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1.amd64",
          "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1.arm64",
          "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-15661"
        },
        {
          "category": "external",
          "summary": "https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d",
          "url": "https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d"
        },
        {
          "category": "external",
          "summary": "https://github.com/libssh2/libssh2/pull/1705",
          "url": "https://github.com/libssh2/libssh2/pull/1705"
        },
        {
          "category": "external",
          "summary": "https://github.com/libssh2/libssh2/pull/1717",
          "url": "https://github.com/libssh2/libssh2/pull/1717"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/libssh2-heap-buffer-over-read-via-sftp-symlink-in-sftp-c",
          "url": "https://www.vulncheck.com/advisories/libssh2-heap-buffer-over-read-via-sftp-symlink-in-sftp-c"
        }
      ],
      "release_date": "2026-06-18T21:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-09-07T14:41:18.599999Z",
          "details": "CVE-2025-15661 is a client-side SFTP parsing flaw in libssh2 reachable only when a host initiates an SFTP session and processes SSH_FXP_NAME replies to READLINK/REALPATH; systems acting solely as SSH/SFTP servers are not exposed. Exploitation requires connecting to a malicious or compromised SSH server, or a man‑in‑the‑middle that successfully bypasses SSH host‑key verification, and the effect is limited to a client process crash or minor heap disclosure without integrity impact or code execution. If your systems do not use libssh2 for outbound SFTP to untrusted endpoints, this issue can be safely deprioritized.",
          "product_ids": [
            "Debian-11:libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
            "Debian-11:libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
            "Debian-11:libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
            "Debian-11:libssh2-1-0:1.9.0-2+deb11u1.amd64",
            "Debian-11:libssh2-1-0:1.9.0-2+deb11u1.arm64",
            "Debian-11:libssh2-1-0:1.9.0-2+deb11u1.armel",
            "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
            "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
            "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
            "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1.amd64",
            "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1.arm64",
            "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1.armel"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Debian-11:libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
            "Debian-11:libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
            "Debian-11:libssh2-1-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
            "Debian-11:libssh2-1-0:1.9.0-2+deb11u1.amd64",
            "Debian-11:libssh2-1-0:1.9.0-2+deb11u1.arm64",
            "Debian-11:libssh2-1-0:1.9.0-2+deb11u1.armel",
            "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.amd64",
            "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.arm64",
            "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1+tuxcare.els1.armel",
            "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1.amd64",
            "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1.arm64",
            "Debian-11:libssh2-1-dev-0:1.9.0-2+deb11u1.armel"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}