Project: libssh

Language c
OSS-Fuzz project link
Project repository link
Build status: Fuzzers succeeding: Build log
Build status: Code coverage succeeding: Build log
Build status: Fuzz Introspector succeeding: Build log
Fuzzer count 7
Lines of code 29865
Lines covered 11175
Code coverage 37.42%
Code coverage report Report link
Static reachability 59.40%
Fuzz Introspector report Report link (from 2025-03-27)
Fuzzer Code coverage (lines) Latest Report Comments
ssh_bind_config_fuzzer 3.34% (avg: 3.39%, max: 3.54%) 2025-03-27
ssh_client_config_fuzzer 8.62% (avg: 8.29%, max: 8.94%) 2025-03-27
ssh_client_fuzzer 21.55% (avg: 22.39%, max: 24.1%) 2025-03-27
ssh_known_hosts_fuzzer 4.79% (avg: 4.81%, max: 4.85%) 2025-03-27
ssh_privkey_fuzzer 0.71% (avg: 0.71%, max: 0.72%) 2025-03-27
ssh_pubkey_fuzzer 4.0% (avg: 4.01%, max: 4.01%) 2025-03-27
ssh_server_fuzzer 20.09% (avg: 20.45%, max: 20.89%) 2025-03-27

Historical Progression

Jul 2023Jan 2024Jul 2024Jan 2025020406080100
Code Coverage (lines) %DateCoverage
Jul 2023Jan 2024Jul 2024Jan 2025024681012
Fuzzer countDateFuzzers
Jul 2023Jan 2024Jul 2024Jan 2025020406080100
Code Coverage (functions) %DateCoverage
Jul 2023Jan 2024Jul 2024Jan 2025020406080100
Static reachability %DateReachability

Per Fuzzer Progression

Mar 22025Mar 9Mar 16Mar 23020406080100
Code Coverage (lines) %ssh_pubkey_fuzzerDateCoverage
Mar 22025Mar 9Mar 16Mar 23020406080100
Code Coverage (lines) %ssh_known_hosts_fuzzerDateCoverage
Mar 22025Mar 9Mar 16Mar 23020406080100
Code Coverage (lines) %ssh_privkey_fuzzerDateCoverage
Mar 22025Mar 9Mar 16Mar 23020406080100
Code Coverage (lines) %ssh_client_fuzzerDateCoverage
Mar 22025Mar 9Mar 16Mar 23020406080100
Code Coverage (lines) %ssh_server_fuzzerDateCoverage
Mar 22025Mar 9Mar 16Mar 23020406080100
Code Coverage (lines) %ssh_bind_config_fuzzerDateCoverage
Mar 22025Mar 9Mar 16Mar 23020406080100
Code Coverage (lines) %ssh_client_config_fuzzerDateCoverage

Functions of interest to fuzz

This section outlines functions that may be of interest to fuzz. They are based on ranking functions that have a lot of complexity but currently exhibit low code coverage. The complexity is calculated based on the function itself as well as the functions called by the given function, i.e. the tree of code that the function triggers.


This is only a minor amount of introspection information available for this project. Please consult the Fuzz Introspector report for more information, e.g. the introspection table of all functions in the target project available here.