A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssh-clientsUpgrade pam_ssh_agent_authUpgrade openssh-serverUpgrade openssh-askpassUpgrade openssh-keycatUpgrade openssh | Aug 2, 2026 | Jul 29, 2026 |
| Redhat_linux | — | Upgrade openssh-askpassUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-keysignUpgrade openssh-debuginfoUpgrade opensshUpgrade openssh-serverUpgrade openssh-keycat-debuginfoUpgrade openssh-clientsUpgrade openssh-askpass-debuginfoUpgrade openssh-sk-dummy-debuginfoUpgrade openssh-debugsourceUpgrade openssh-keysign-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-clients-debuginfoUpgrade openssh-keycatUpgrade pam_ssh_agent_auth | Jul 17, 2026 | Jun 22, 2026 |
| Rocky_linux | — | Upgrade pam_ssh_agent_authUpgrade openssh-clients-debuginfoUpgrade openssh-clientsUpgrade opensshUpgrade openssh-askpassUpgrade openssh-server-debuginfoUpgrade openssh-keycatUpgrade openssh-debugsourceUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-serverUpgrade openssh-debuginfoUpgrade openssh-askpass-debuginfoUpgrade openssh-keycat-debuginfo | Aug 3, 2026 | Jul 30, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub