Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-60002

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

A flaw was found in OpenSSH. A remote attacker could exploit a use-after-free vulnerability on the client side when a server changes its host key during a key re-exchange. This could lead to high impact on confidentiality and integrity, and low impact on availability.

Отчет

This Important flaw in OpenSSH client could allow a malicious SSH server to execute arbitrary code on the connecting client due to a use-after-free vulnerability during host key re-exchange. While requiring a connection to a specially crafted server, the potential for high impact on client confidentiality and integrity elevates the severity beyond Moderate.

Меры по смягчению последствий

To mitigate this issue, OpenSSH clients should only connect to trusted SSH servers. Enforcing strict host key checking and carefully managing known_hosts files can help prevent connections to servers with unexpected or altered host keys, thereby reducing exposure to this client-side vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6opensshAffected
Red Hat Enterprise Linux 7opensshAffected
Red Hat Enterprise Linux 8opensshAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10opensshFixedRHSA-2026:4775730.07.2026
Red Hat Enterprise Linux 9opensshFixedRHSA-2026:4775629.07.2026
Red Hat Enterprise Linux 9opensshFixedRHSA-2026:4775629.07.2026
Red Hat Hardened Imagesopenssh-main-10.4p1-1.hum1FixedRHSA-2026:3738209.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2497936openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side

EPSS

Процентиль: 22%
0.003
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
25 дней назад

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

CVSS3: 7.7
nvd
25 дней назад

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

CVSS3: 7.7
msrc
24 дня назад

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

CVSS3: 7.7
debian
25 дней назад

ssh in OpenSSH before 10.4 can have a use-after-free when a server cha ...

CVSS3: 7.7
github
25 дней назад

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

EPSS

Процентиль: 22%
0.003
Низкий

7.7 High

CVSS3