The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.042
EPSS Ranking 88.0%