Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-60002

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 7.7

Описание

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

A flaw was found in OpenSSH. A remote attacker could exploit a use-after-free vulnerability on the client side when a server changes its host key during a key re-exchange. This could lead to high impact on confidentiality and integrity, and low impact on availability.

Отчет

This Important flaw in OpenSSH client could allow a malicious SSH server to execute arbitrary code on the connecting client due to a use-after-free vulnerability during host key re-exchange. While requiring a connection to a specially crafted server, the potential for high impact on client confidentiality and integrity elevates the severity beyond Moderate.

Меры по смягчению последствий

To mitigate this issue, OpenSSH clients should only connect to trusted SSH servers. Enforcing strict host key checking and carefully managing known_hosts files can help prevent connections to servers with unexpected or altered host keys, thereby reducing exposure to this client-side vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6opensshNot affected
Red Hat Enterprise Linux 7opensshNot affected
Red Hat Enterprise Linux 8opensshNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Not affected
Red Hat Enterprise Linux 10opensshFixedRHSA-2026:4775730.07.2026
Red Hat Enterprise Linux 9opensshFixedRHSA-2026:4775629.07.2026
Red Hat Enterprise Linux 9opensshFixedRHSA-2026:4775629.07.2026
Red Hat OpenShift Container Platform 4.22rhcos-4.22.9.8.202608130832FixedRHSA-2026:5476918.08.2026
Red Hat Hardened Imagesopenssh-main-10.4p1-1.hum1FixedRHSA-2026:3738209.07.2026
Red Hat Update Infrastructure 5rhui5/installer-rhel9FixedRHSA-2026:5438712.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2497936openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
2 месяца назад

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

CVSS3: 7.7
nvd
2 месяца назад

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

CVSS3: 7.7
msrc
2 месяца назад

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

CVSS3: 7.7
debian
2 месяца назад

ssh in OpenSSH before 10.4 can have a use-after-free when a server cha ...

CVSS3: 7.7
github
2 месяца назад

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

7.7 High

CVSS3