CVE-2020-16135: Null Pointer Dereference
Last updated 25 August 2025
Other sources
libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if sshbuffernew returns NULL.
— Launchpad
Libssh is vulnerable to a denial of service, caused by a NULL pointer dereference in tftpserver.c if sshbuffernew returns NULL. A remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-16135?
CVE-2020-16135 is a vulnerability in Libssh that can lead to a denial of service by causing the application to crash.
What software is affected by CVE-2020-16135?
CVE-2020-16135 affects IBM QRadar SIEM versions 7.5.0 GA, 7.4.3 GA - 7.4.3 FP4, and 7.3.3 GA - 7.3.3 FP10.
How severe is CVE-2020-16135?
CVE-2020-16135 has a severity rating of 7.5 (high).
How can I fix CVE-2020-16135?
To fix CVE-2020-16135, you can apply the official patches provided by IBM for the affected versions of QRadar SIEM. You can find the patches on the IBM Support website.
Where can I find more information about CVE-2020-16135?
You can find more information about CVE-2020-16135 on the following websites: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1862457), [Gentoo](https://bugs.gentoo.org/734624), and [GitLab](https://gitlab.com/libssh/libssh-mirror/-/commit/533d881b0f4b24c72b35ecc97fa35d295d063e53).