3.7
CVE-2026-106582
- EPSS 0.18%
- Veröffentlicht 06.10.2026 20:35:32
- Zuletzt bearbeitet 07.10.2026 15:17:18
- Erkennungen
In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 "Crossing the Streams" findings.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerOpenBSD
≫
Produkt
OpenSSH
Default Statusunaffected
Version
0
Version <
10.6
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.071 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-514 Covert Channel
A covert channel is a path that can be used to transfer information in a way not intended by the system's designers.
https://www.openssh.org/releasenotes.html#10.6
https://arxiv.org/abs/2609.07709