Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-60000

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

A flaw was found in OpenSSH's Secure Shell Daemon (sshd). This vulnerability allows a remote attacker to cause a denial of service by initiating an excessive number of authentication attempts. The issue arises from the mishandling of the MaxAuthTries setting specifically when using GSSAPIAuthentication, leading to resource exhaustion.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10opensshFix deferred
Red Hat Enterprise Linux 6opensshFix deferred
Red Hat Enterprise Linux 7opensshFix deferred
Red Hat Enterprise Linux 8opensshFix deferred
Red Hat Enterprise Linux 9opensshFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesopenssh-main-10.4p1-1.hum1FixedRHSA-2026:3738209.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-307
https://bugzilla.redhat.com/show_bug.cgi?id=2497946openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts

EPSS

Процентиль: 36%
0.00441
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
25 дней назад

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

CVSS3: 3.7
nvd
25 дней назад

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

CVSS3: 3.7
msrc
24 дня назад

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

CVSS3: 3.7
debian
25 дней назад

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial ...

CVSS3: 3.7
github
25 дней назад

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

EPSS

Процентиль: 36%
0.00441
Низкий

5.9 Medium

CVSS3