CVE-2023-25136
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 90%
exploitation probability
90%top 1% of all CVEs
observed exploitation
nono source reports it
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."
Affected products
n/a · n/aReferences
https://bugzilla.mindrot.org/show_bug.cgi?id=3522https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/017_sshd.patch.sighttps://github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JGAUIXJ3TEKCRKVWFQ6GDAGQFTIIGQQP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7LKQDFZWKYHQ65TBSH2X2HJQ4V2THS3/https://news.ycombinator.com/item?id=34711565https://security.gentoo.org/glsa/202307-01https://security.netapp.com/advisory/ntap-20230309-0003/https://www.openwall.com/lists/oss-security/2023/02/02/2http://www.openwall.com/lists/oss-security/2023/02/13/1http://www.openwall.com/lists/oss-security/2023/02/22/1