5.9
CVE-2025-26466
- EPSS 39.85%
- Veröffentlicht 28.02.2025 22:15:40
- Zuletzt bearbeitet 08.10.2026 12:17:13
- Erkennungen
Openssh: denial-of-service in openssh
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 24.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 24.10
Debian ≫ Debian Linux Version 11.0
Debian ≫ Debian Linux Version 12.0
Debian ≫ Debian Linux Version 13.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 39.85% | 0.985 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| RedHat | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://www.openwall.com/lists/oss-security/2025/02/18/1
https://www.openwall.com/lists/oss-security/2025/02/18/4
https://seclists.org/oss-sec/2025/q1/144
https://bugzilla.redhat.com/show_bug.cgi?id=2345043
https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt
https://security.netapp.com/advisory/ntap-20250228-0002/
https://bugzilla.suse.com/show_bug.cgi?id=1237041
https://www.vicarius.io/vsociety/posts/cve-2025-26466-detection-script-memory-consumption-vulnerability-in-openssh
https://www.vicarius.io/vsociety/posts/cve-2025-26466-mitigation-script-memory-consumption-vulnerability-in-openssh
http://seclists.org/fulldisclosure/2025/Feb/18
http://seclists.org/fulldisclosure/2025/May/7
http://seclists.org/fulldisclosure/2025/May/8
https://access.redhat.com/security/cve/CVE-2025-26466
https://security-tracker.debian.org/tracker/CVE-2025-26466
https://ubuntu.com/security/CVE-2025-26466
https://access.redhat.com/errata/RHBA-2025:6305