Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55654

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.

Отчет

This flaw is rated Low. A heap out-of-bounds read in OpenSSH's GSSAPI authentication component can lead to a denial of service. Exploitation requires GSSAPIAuthentication to be explicitly enabled, which is not the default configuration in Red Hat products, and a Kerberos environment providing authenticated auth-indicators. The impact is limited to the availability of the SSH authentication process. This vulnerability doesn't affect the upstream OpenSSH versions and is restricted to the versions as shipped with Red Hat Enterprise Linux.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6opensshAffected
Red Hat Enterprise Linux 7opensshAffected
Red Hat Enterprise Linux 8opensshAffected
Red Hat OpenShift Container Platform 4rhcosUnder investigation
Red Hat Enterprise Linux 10opensshFixedRHSA-2026:4775730.07.2026
Red Hat Enterprise Linux 9opensshFixedRHSA-2026:4775629.07.2026
Red Hat Enterprise Linux 9opensshFixedRHSA-2026:4775629.07.2026
Red Hat Hardened Imagesopenssh-main-10.3p1-6.hum1FixedRHSA-2026:3675908.07.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2462493openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination

EPSS

Процентиль: 36%
0.00432
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 1 месяца назад

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.

CVSS3: 3.7
nvd
около 1 месяца назад

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.

CVSS3: 3.7
debian
около 1 месяца назад

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds ...

CVSS3: 3.7
github
около 1 месяца назад

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.

rocky
4 дня назад

Important: openssh security update

EPSS

Процентиль: 36%
0.00432
Низкий

3.7 Low

CVSS3