/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2023-25136

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-25136

CGA ID

CGA-fc65-vmxv-8jfh

Severity

6.5

Medium

CVSS V3

Description

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images