An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade nerdctlUpgrade containerdUpgrade containerd-debuginfoUpgrade amazon-ssm-agentUpgrade amazon-cloudwatch-agentUpgrade nerdctl-debuginfoUpgrade containerd-stressUpgrade runfinch-finch | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade runfinch-finchUpgrade rclone-debuginfoUpgrade amazon-cloudwatch-agentUpgrade containerd-stressUpgrade amazon-ssm-agentUpgrade rclone-debugsourceUpgrade containerd-stress-debuginfoUpgrade containerdUpgrade nerdctlUpgrade containerd-debuginfoUpgrade rcloneUpgrade containerd-debugsource | Jun 9, 2026 | May 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub