CVE-2025-26466

NameCVE-2025-26466
DescriptionDenial of Service: asymmetric resource consumption of memory and CPU
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openssh (PTS)bullseye1:8.4p1-5+deb11u3fixed
bullseye (security)1:8.4p1-5+deb11u4fixed
bookworm1:9.2p1-2+deb12u4fixed
bookworm (security)1:9.2p1-2+deb12u5fixed
trixie1:9.9p1-3vulnerable
sid1:9.9p2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opensshsourcebullseye(not affected)
opensshsourcebookworm(not affected)
opensshsource(unstable)1:9.9p2-1

Notes

[bookworm] - openssh <not-affected> (Vulnerable code introduced later)
[bullseye] - openssh <not-affected> (Vulnerable code introduced later)
https://www.openssh.com/releasenotes.html#9.9p2
https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt
Introduced with: https://github.com/openssh/openssh-portable/commit/dce6d80d2ed3cad2c516082682d5f6ca877ef714 (V_9_5_P1)
Fixed by: https://github.com/openssh/openssh-portable/commit/6ce00f0c2ecbb9f75023dbe627ee6460bcec78c2 (V_9_9_P1)

Search for package or bug name: Reporting problems