Описание
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
A flaw was found in OpenSSH. A remote attacker could exploit a use-after-free vulnerability on the client side when a server changes its host key during a key re-exchange. This could lead to high impact on confidentiality and integrity, and low impact on availability.
Отчет
This Important flaw in OpenSSH client could allow a malicious SSH server to execute arbitrary code on the connecting client due to a use-after-free vulnerability during host key re-exchange. While requiring a connection to a specially crafted server, the potential for high impact on client confidentiality and integrity elevates the severity beyond Moderate.
Меры по смягчению последствий
To mitigate this issue, OpenSSH clients should only connect to trusted SSH servers. Enforcing strict host key checking and carefully managing known_hosts files can help prevent connections to servers with unexpected or altered host keys, thereby reducing exposure to this client-side vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssh | Affected | ||
| Red Hat Enterprise Linux 7 | openssh | Affected | ||
| Red Hat Enterprise Linux 8 | openssh | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Affected | ||
| Red Hat Enterprise Linux 10 | openssh | Fixed | RHSA-2026:47757 | 30.07.2026 |
| Red Hat Enterprise Linux 9 | openssh | Fixed | RHSA-2026:47756 | 29.07.2026 |
| Red Hat Enterprise Linux 9 | openssh | Fixed | RHSA-2026:47756 | 29.07.2026 |
| Red Hat Hardened Images | openssh-main-10.4p1-1.hum1 | Fixed | RHSA-2026:37382 | 09.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.7 High
CVSS3
Связанные уязвимости
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
ssh in OpenSSH before 10.4 can have a use-after-free when a server cha ...
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
EPSS
7.7 High
CVSS3