Описание
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
Отчет
This flaw is rated Low. A heap out-of-bounds read in OpenSSH's GSSAPI authentication component can lead to a denial of service. Exploitation requires GSSAPIAuthentication to be explicitly enabled, which is not the default configuration in Red Hat products, and a Kerberos environment providing authenticated auth-indicators. The impact is limited to the availability of the SSH authentication process.
This vulnerability doesn't affect the upstream OpenSSH versions and is restricted to the versions as shipped with Red Hat Enterprise Linux.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssh | Affected | ||
| Red Hat Enterprise Linux 7 | openssh | Affected | ||
| Red Hat Enterprise Linux 8 | openssh | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Under investigation | ||
| Red Hat Enterprise Linux 10 | openssh | Fixed | RHSA-2026:47757 | 30.07.2026 |
| Red Hat Enterprise Linux 9 | openssh | Fixed | RHSA-2026:47756 | 29.07.2026 |
| Red Hat Enterprise Linux 9 | openssh | Fixed | RHSA-2026:47756 | 29.07.2026 |
| Red Hat Hardened Images | openssh-main-10.3p1-6.hum1 | Fixed | RHSA-2026:36759 | 08.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.7 Low
CVSS3
Связанные уязвимости
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds ...
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
EPSS
3.7 Low
CVSS3