VDB
CISA-2025-26465
CISA-2025-26465
PUBLISHED
CVSS 6.8 MEDIUM
Reported by redhat · Published February 18, 2025
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
Risk Scores
CVSS 3.1
6.8
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 6.8p1 | ||
| Red Hat | Red Hat Enterprise Linux 8 | 0:8.0p1-26.el8_10 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:8.0p1-26.el8_10 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:8.7p1-45.el9 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:8.7p1-45.el9 |
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | 0:8.7p1-38.el9_4.5 |
| Red Hat | Red Hat Discovery 1.14 | sha256:f33991d766b618a128fb99fbe4f9b61c5004f7c6aa73b2b38e28d59e56c64d63 |
| Red Hat | Red Hat Enterprise Linux 10 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat Enterprise Linux 8 | 0:8.0p1-26.el8_10, 0:8.0p1-26.el8_10, 0:8.0p1-26.el8_10 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat Enterprise Linux 10 | |
| Red Hat | Red Hat Discovery 1.14 | sha256:f33991d766b618a128fb99fbe4f9b61c5004f7c6aa73b2b38e28d59e56c64d63, sha256:f33991d766b618a128fb99fbe4f9b61c5004f7c6aa73b2b38e28d59e56c64d63 |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 9 | 0:8.7p1-45.el9, 0:8.7p1-45.el9, 0:8.7p1-45.el9 |
| 6.8p1, * | ||
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | 0:8.7p1-38.el9_4.5, * |
| Red Hat | Red Hat Enterprise Linux 6 |
Timeline
- Feb 18, 2025 CVE Published
- Jan 29, 2026 CVE Updated
- Apr 26, 2026 Distribution Patch
- Apr 26, 2026 Distribution Patch
- Apr 26, 2026 Distribution Patch
- Apr 26, 2026 Distribution Patch
- Apr 26, 2026 Security Advisory
- Apr 26, 2026 Security Advisory
- Apr 26, 2026 Security Advisory
- Apr 26, 2026 Security Advisory
References
- RHSA-2025:16823 vendor-advisoryx_refsource_REDHAT
- RHSA-2025:3837 vendor-advisoryx_refsource_REDHAT
- RHSA-2025:6993 vendor-advisoryx_refsource_REDHAT
- RHSA-2025:8385 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2344780 issue-trackingx_refsource_REDHAT
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html url
- https://www.openwall.com/lists/oss-security/2025/02/18/1 url
- https://www.openwall.com/lists/oss-security/2025/02/18/4 url
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/ url
- https://bugzilla.suse.com/show_bug.cgi?id=1237040 url
- https://security-tracker.debian.org/tracker/CVE-2025-26465 url
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig url
- https://ubuntu.com/security/CVE-2025-26465 url
- https://www.openssh.com/releasenotes.html#9.9p2 url
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-discovers-two-vulnerabilities-in-openssh-cve-2025-26465-cve-2025-26466 url
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.html url
- https://security.netapp.com/advisory/ntap-20250228-0003/ url
…and 5 more