CVE-2020-1730

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-1730

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2020:4545

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-1730.html

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202004-11

OS impact

OSVersionStatusFixed in
arch archfixed0.9.4-1
suse slesaffected
rockylinux rocky8fixed
debian debianbookwormfixed0.9.4-1
debian debianbullseyefixed0.9.4-1
debian debianforkyfixed0.9.4-1
debian debiansidfixed0.9.4-1
debian debiantrixiefixed0.9.4-1

References

Verify integrity in audit chain (admin only). AS-IS.