Логотип exploitDog
bind:"GHSA-m92w-x6j2-5gc5" OR bind:"CVE-2025-26466"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-m92w-x6j2-5gc5" OR bind:"CVE-2025-26466"

Количество 8

Количество 8

github логотип

GHSA-m92w-x6j2-5gc5

6 месяцев назад

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.

CVSS3: 5.9
EPSS: Средний
ubuntu логотип

CVE-2025-26466

6 месяцев назад

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.

CVSS3: 5.9
EPSS: Средний
redhat логотип

CVE-2025-26466

6 месяцев назад

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.

CVSS3: 5.9
EPSS: Средний
nvd логотип

CVE-2025-26466

6 месяцев назад

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.

CVSS3: 5.9
EPSS: Средний
msrc логотип

CVE-2025-26466

6 месяцев назад

CVSS3: 5.9
EPSS: Средний
debian логотип

CVE-2025-26466

6 месяцев назад

A flaw was found in the OpenSSH package. For each ping packet the SSH ...

CVSS3: 5.9
EPSS: Средний
fstec логотип

BDU:2025-01893

6 месяцев назад

Уязвимость сервера средства криптографической защиты OpenSSH, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2025:0585-1

6 месяцев назад

Security update for openssh

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m92w-x6j2-5gc5

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.

CVSS3: 5.9
42%
Средний
6 месяцев назад
ubuntu логотип
CVE-2025-26466

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.

CVSS3: 5.9
42%
Средний
6 месяцев назад
redhat логотип
CVE-2025-26466

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.

CVSS3: 5.9
42%
Средний
6 месяцев назад
nvd логотип
CVE-2025-26466

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.

CVSS3: 5.9
42%
Средний
6 месяцев назад
msrc логотип
CVSS3: 5.9
42%
Средний
6 месяцев назад
debian логотип
CVE-2025-26466

A flaw was found in the OpenSSH package. For each ping packet the SSH ...

CVSS3: 5.9
42%
Средний
6 месяцев назад
fstec логотип
BDU:2025-01893

Уязвимость сервера средства криптографической защиты OpenSSH, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
42%
Средний
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0585-1

Security update for openssh

6 месяцев назад

Уязвимостей на страницу