vulnerability
Gentoo Linux: CVE-2023-25136: OpenSSH: Remote Code Execution
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:M/Au:N/C:N/I:P/A:C) | Feb 3, 2023 | Jul 20, 2023 | Mar 31, 2026 |
Severity
8
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:C)
Published
Feb 3, 2023
Added
Jul 20, 2023
Modified
Mar 31, 2026
Description
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."
Solution
gentoo-linux-upgrade-net-misc-openssh
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.