Описание
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
A flaw was found in OpenSSH. The sshd component has an undocumented security-relevant behavior where GSSAPIStrictAcceptorCheck has no value when the server is in a Windows Active Directory environment. This could lead to unintended information disclosure and impact data integrity.
Меры по смягчению последствий
To mitigate this issue, avoid using GSSAPI authentication for sshd when the server is integrated with a Windows Active Directory environment. If GSSAPI authentication is not strictly required, it can be disabled by setting GSSAPIAuthentication no in the /etc/ssh/sshd_config file. After modifying the configuration, the sshd service must be restarted for the changes to take effect. Note that restarting the sshd service will terminate all active SSH sessions.
Alternatively, if GSSAPI authentication is necessary in such an environment, ensure that the network path between the client and the sshd server, and to the Active Directory, is secured and trusted to prevent man-in-the-middle attacks.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | openssh | Fix deferred | ||
| Red Hat Enterprise Linux 6 | openssh | Fix deferred | ||
| Red Hat Enterprise Linux 7 | openssh | Fix deferred | ||
| Red Hat Enterprise Linux 8 | openssh | Fix deferred | ||
| Red Hat Enterprise Linux 9 | openssh | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Hardened Images | openssh-main-10.4p1-1.hum1 | Fixed | RHSA-2026:37382 | 09.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.8 Medium
CVSS3
Связанные уязвимости
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
sshd in OpenSSH before 10.4 has an undocumented security-relevant beha ...
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
EPSS
4.8 Medium
CVSS3