Описание
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
A flaw was found in OpenSSH where the SSH client accepted \0 (null) characters in ssh:// URIs. When a ProxyCommand is configured, these characters could alter how the command is parsed, potentially leading to code execution depending on how the proxy is set up.
Отчет
The impact is MODERATE because it is a critical component used across many Red Hat products. Exploiting this vulnerability would require a specific configuration where ProxyCommand is enabled and the SSH client processes an untrusted ssh:// URI containing null bytes. Under these conditions, the command parser may misinterpret the URI and execute unintended shell commands.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssh | Fix deferred | ||
| Red Hat Enterprise Linux 7 | openssh | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Enterprise Linux 10 | openssh | Fixed | RHSA-2025:23479 | 17.12.2025 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | openssh | Fixed | RHSA-2026:1678 | 02.02.2026 |
| Red Hat Enterprise Linux 8 | openssh | Fixed | RHSA-2025:23481 | 17.12.2025 |
| Red Hat Enterprise Linux 8 | openssh | Fixed | RHSA-2025:23481 | 17.12.2025 |
| Red Hat Enterprise Linux 9 | openssh | Fixed | RHSA-2025:23480 | 17.12.2025 |
| Red Hat Enterprise Linux 9 | openssh | Fixed | RHSA-2025:23480 | 17.12.2025 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | openssh | Fixed | RHSA-2026:1790 | 03.02.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, ...
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
EPSS
5.3 Medium
CVSS3