Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73282

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 5.6
EPSS Низкий

Описание

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

A flaw was found in OpenSSH. A use-after-free vulnerability exists in the ssh client when handling concurrent remote-forwarding operations. This can occur if a remote forwarding is added via the local session multiplexing socket while a remote forwarding open request is pending with the server. A remote attacker with high attack complexity could potentially exploit this to achieve low impact on confidentiality and integrity.

Отчет

A use-after-free flaw exists in OpenSSH's ssh client during concurrent remote-forwarding processing. When adding a remote forward via the local session multiplexing socket while a server remote-forward open request is pending, realloc data management fails, freeing memory that remains actively referenced. A remote attacker with high attack complexity can exploit this timing window to corrupt process memory, posing a low impact to confidentiality, integrity, and availability.

Меры по смягчению последствий

Avoid issuing dynamic remote-forwarding commands over active SSH multiplexing connections, or disable socket multiplexing by setting ControlMaster no in ~/.ssh/config.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10opensshAffected
Red Hat Enterprise Linux 6opensshFix deferred
Red Hat Enterprise Linux 7opensshFix deferred
Red Hat Enterprise Linux 8opensshFix deferred
Red Hat Enterprise Linux 9opensshFix deferred
Red Hat Hardened ImagesopensshAffected
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2514328openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client

EPSS

Процентиль: 6%
0.00163
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
17 дней назад

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

CVSS3: 4.8
nvd
17 дней назад

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

msrc
14 дней назад

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

CVSS3: 4.8
debian
17 дней назад

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can o ...

CVSS3: 4.8
github
17 дней назад

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

EPSS

Процентиль: 6%
0.00163
Низкий

5.6 Medium

CVSS3