6.8 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): NONE
Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
References
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://seclists.org/oss-sec/2025/q1/144 exploit
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://seclists.org/oss-sec/2025/q1/144 exploit
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://seclists.org/oss-sec/2025/q1/144 exploit
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://seclists.org/oss-sec/2025/q1/144 exploit
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://seclists.org/oss-sec/2025/q1/144 exploit
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://seclists.org/oss-sec/2025/q1/144 exploit
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://seclists.org/oss-sec/2025/q1/144 exploit
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://seclists.org/oss-sec/2025/q1/144
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- RHSA-2025:8385 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://seclists.org/oss-sec/2025/q1/144
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- RHSA-2025:8385 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://seclists.org/oss-sec/2025/q1/144
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- RHSA-2025:8385 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://seclists.org/oss-sec/2025/q1/144
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHSA-2025:8385 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://seclists.org/oss-sec/2025/q1/144
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHSA-2025:16823 x_refsource_REDHAT vendor-advisory
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- RHSA-2025:8385 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://seclists.org/oss-sec/2025/q1/144
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHSA-2025:16823 x_refsource_REDHAT vendor-advisory
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- RHSA-2025:8385 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://seclists.org/oss-sec/2025/q1/144
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHSA-2025:16823 x_refsource_REDHAT vendor-advisory
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- RHSA-2025:8385 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- https://access.redhat.com/solutions/7109879
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://seclists.org/oss-sec/2025/q1/144
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHSA-2025:16823 x_refsource_REDHAT vendor-advisory
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- RHSA-2025:8385 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- https://access.redhat.com/solutions/7109879
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://seclists.org/oss-sec/2025/q1/144
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- http://seclists.org/fulldisclosure/2025/May/8
- http://seclists.org/fulldisclosure/2025/May/7
- http://seclists.org/fulldisclosure/2025/Feb/18
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://seclists.org/oss-sec/2025/q1/144 exploit
- RHSA-2025:16823 x_refsource_REDHAT vendor-advisory
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- RHSA-2025:8385 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- https://access.redhat.com/solutions/7109879
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://seclists.org/oss-sec/2025/q1/144
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- http://seclists.org/fulldisclosure/2025/May/8
- http://seclists.org/fulldisclosure/2025/May/7
- http://seclists.org/fulldisclosure/2025/Feb/18
- https://seclists.org/oss-sec/2025/q1/144 exploit
- https://access.redhat.com/solutions/7109879
- RHBZ#2344780 issue-tracking x_refsource_REDHAT
- https://seclists.org/oss-sec/2025/q1/144
- RHSA-2025:16823 x_refsource_REDHAT vendor-advisory
- RHSA-2025:3837 x_refsource_REDHAT vendor-advisory
- RHSA-2025:6993 x_refsource_REDHAT vendor-advisory
- RHSA-2025:8385 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-26465 x_refsource_REDHAT vdb-entry
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-d…
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.…
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opens…
- http://seclists.org/fulldisclosure/2025/May/8
- http://seclists.org/fulldisclosure/2025/May/7
- http://seclists.org/fulldisclosure/2025/Feb/18
- https://seclists.org/oss-sec/2025/q1/144 exploit
Affected products
- =<9.9p1
- *
- *
- *
Matching in nixpkgs
pkgs.opensshTest
Implementation of the SSH protocol
-
nixos-unstable -
- nixpkgs-unstable 10.0p2
pkgs.openssh_hpn
Implementation of the SSH protocol with high performance networking patches
-
nixos-unstable -
- nixpkgs-unstable 10.0p2
pkgs.openssh_gssapi
Implementation of the SSH protocol with GSSAPI support
-
nixos-unstable -
- nixpkgs-unstable 10.0p2
pkgs.opensshWithKerberos
Implementation of the SSH protocol
-
nixos-unstable -
- nixpkgs-unstable 10.0p2
pkgs.openssh_hpnWithKerberos
Implementation of the SSH protocol with high performance networking patches
-
nixos-unstable -
- nixpkgs-unstable 10.0p2
pkgs.lxqt.lxqt-openssh-askpass
GUI to query passwords on behalf of SSH agents
-
nixos-unstable -
- nixpkgs-unstable 2.2.0
Package maintainers
-
@romildo José Romildo Malaquias <malaquias@gmail.com>
-
@philiptaron Philip Taron <philip.taron@gmail.com>
-
@helsinki-Jo Joachim Ernst <joachim.ernst@helsinki-systems.de>
-
@dasJ Janne Heß <janne@hess.ooo>
-
@Conni2461 Simon Hauser <simon-hauser@outlook.com>
-
@numinit Morgan Jones <me+nixpkgs@numin.it>
-
@wahjava Ashish SHUKLA <ashish.is@lostca.se>