Описание
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | deferred | 2026-06-29 |
| esm-infra-legacy/trusty | deferred | 2026-06-29 |
| esm-infra-legacy/xenial | deferred | 2026-06-29 |
| esm-infra/bionic | deferred | 2026-06-29 |
| esm-infra/focal | deferred | 2026-06-29 |
| fips-preview/jammy | deferred | 2026-06-29 |
| fips-updates/bionic | deferred | 2026-06-29 |
| fips-updates/focal | deferred | 2026-06-29 |
| fips-updates/jammy | deferred | 2026-06-29 |
| fips-updates/noble | deferred | 2026-06-29 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | ignored | |
| esm-apps/bionic | ignored | |
| esm-apps/focal | ignored | |
| esm-apps/jammy | ignored | |
| esm-apps/noble | ignored | |
| esm-apps/resolute | ignored | |
| jammy | ignored | |
| noble | ignored | |
| questing | ignored | |
| resolute | ignored |
Показывать по
EPSS
3.7 Low
CVSS3
Связанные уязвимости
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds ...
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
EPSS
3.7 Low
CVSS3