CVE-2025-26465
בינונית 6.8
תיאור (מקור, אנגלית)
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
מדדים
- CVSS 3.1
-
6.8 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N - EPSS — סבירות ניצול
- 8% (אחוזון 100) נכון ל-9/10/2026
- CWE
- CWE-390
מוצרים מושפעים
openbsd: openssh; netapp: active iq unified manager; netapp: ontap; redhat: openshift container platform; debian: debian linux; redhat: enterprise linux
קישורים
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig Patch
- https://access.redhat.com/errata/RHSA-2025:16823
- https://access.redhat.com/errata/RHSA-2025:3837
- https://access.redhat.com/errata/RHSA-2025:6993
- https://access.redhat.com/errata/RHSA-2025:8385
- https://access.redhat.com/security/cve/CVE-2025-26465 Third Party Advisory
- https://access.redhat.com/solutions/7109879
- https://bugzilla.redhat.com/show_bug.cgi?id=2344780 Issue TrackingThird Party Advisory
- https://seclists.org/oss-sec/2025/q1/144 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2025/Feb/18