Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59998

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

A flaw was found in OpenSSH. The sshd component has an undocumented security-relevant behavior where GSSAPIStrictAcceptorCheck has no value when the server is in a Windows Active Directory environment. This could lead to unintended information disclosure and impact data integrity.

Меры по смягчению последствий

To mitigate this issue, avoid using GSSAPI authentication for sshd when the server is integrated with a Windows Active Directory environment. If GSSAPI authentication is not strictly required, it can be disabled by setting GSSAPIAuthentication no in the /etc/ssh/sshd_config file. After modifying the configuration, the sshd service must be restarted for the changes to take effect. Note that restarting the sshd service will terminate all active SSH sessions.

# echo "GSSAPIAuthentication no" >> /etc/ssh/sshd_config # systemctl restart sshd

Alternatively, if GSSAPI authentication is necessary in such an environment, ensure that the network path between the client and the sshd server, and to the Active Directory, is secured and trusted to prevent man-in-the-middle attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10opensshFix deferred
Red Hat Enterprise Linux 6opensshFix deferred
Red Hat Enterprise Linux 7opensshFix deferred
Red Hat Enterprise Linux 8opensshFix deferred
Red Hat Enterprise Linux 9opensshFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesopenssh-main-10.4p1-1.hum1FixedRHSA-2026:3738209.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-909
https://bugzilla.redhat.com/show_bug.cgi?id=2497935openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory

EPSS

Процентиль: 8%
0.0018
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
25 дней назад

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

CVSS3: 4.8
nvd
25 дней назад

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

msrc
22 дня назад

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

CVSS3: 4.8
debian
25 дней назад

sshd in OpenSSH before 10.4 has an undocumented security-relevant beha ...

CVSS3: 4.8
github
25 дней назад

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

EPSS

Процентиль: 8%
0.0018
Низкий

4.8 Medium

CVSS3