An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade runfinch-finchUpgrade containerd-stressUpgrade nerdctl-debuginfoUpgrade nerdctlUpgrade containerd-debuginfoUpgrade amazon-cloudwatch-agentUpgrade amazon-ssm-agentUpgrade containerd | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade rcloneUpgrade containerd-debugsourceUpgrade containerd-stress-debuginfoUpgrade runfinch-finchUpgrade amazon-ssm-agentUpgrade containerd-stressUpgrade containerdUpgrade nerdctlUpgrade rclone-debuginfoUpgrade containerd-debuginfoUpgrade amazon-cloudwatch-agentUpgrade rclone-debugsource | Jun 9, 2026 | May 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub