CVE-2025-14282
published 2026-02-12CVE-2025-14282: A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the…
PriorityP434medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.36%
28.6th percentile
A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root,
only switching to the logged-in user upon spawning a shell or performing
some operations like reading the user's files.
With the recent ability of also using unix domain sockets as the forwarding destination any user able to log in via ssh can connect to any unix socket with the root's credentials, bypassing both file system restrictions and any SO_PEERCRED / SO_PASSCRED checks performed by the peer.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dropbear | < dropbear 2025.89-1 (forky) | dropbear 2025.89-1 (forky) |
| https | github.com_mkj_dropbear_dropbear | >= 0 < 2025.89-1~deb13u1 | 2025.89-1~deb13u1 |
| https | github.com_mkj_dropbear_dropbear | >= 0 < 2025.89-1 | 2025.89-1 |
| https | github.com_mkj_dropbear_dropbear | >= 2024.84 < 2025.88 | 2025.88 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
osv5.4MEDIUM
vendor_debian5.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xqcm-jrw9-wq72: A flaw was found in Dropbear
ghsa_unreviewed·2026-02-13
CVE-2025-14282 [MEDIUM] CWE-266 GHSA-xqcm-jrw9-wq72: A flaw was found in Dropbear
A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files. With the recent ability of also using unix domain sockets as the forwarding destination any user able to log in via ssh can connect to any unix socket with the root's credentials, bypassing both file system restrictions and any SO_PEERCRED / SO_PASSCRED checks performed by the peer.
OSV
CVE-2025-14282: A flaw was found in Dropbear
osv·2026-02-12·CVSS 5.4
CVE-2025-14282 [MEDIUM] CVE-2025-14282: A flaw was found in Dropbear
A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files. With the recent ability of also using unix domain sockets as the forwarding destination any user able to log in via ssh can connect to any unix socket with the root's credentials, bypassing both file system restrictions and any SO_PEERCRED / SO_PASSCRED checks performed by the peer.
Debian
CVE-2025-14282: dropbear - A flaw was found in Dropbear. When running in multi-user mode and authenticating...
vendor_debian·2025·CVSS 5.4
CVE-2025-14282 [MEDIUM] CVE-2025-14282: dropbear - A flaw was found in Dropbear. When running in multi-user mode and authenticating...
A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files. With the recent ability of also using unix domain sockets as the forwarding destination any user able to log in via ssh can connect to any unix socket with the root's credentials, bypassing both file system restrictions and any SO_PEERCRED / SO_PASSCRED checks performed by the peer.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 2025.89-1)
sid: resolved (fixed in 2025.89-1)
trixie: resolved (fixed in 2025.89-1~deb13u1)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2025-14282https://bugzilla.redhat.com/show_bug.cgi?id=2420052https://github.com/mkj/dropbear/pull/391https://github.com/mkj/dropbear/pull/394https://lists.ucc.gu.uwa.edu.au/pipermail/dropbear/2025q4/002390.htmlhttp://www.openwall.com/lists/oss-security/2025/12/16/4http://www.openwall.com/lists/oss-security/2025/12/17/1
2026-02-12
Published