cbcvebase.
CVE-2025-26465
published 2025-02-18

CVE-2025-26465: A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine…

PriorityP345medium6.8CVSS 3.1
AVNACHPRNUIRSUCHIHAN
EPSS
7.45%
93.8th percentile
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
applemacos_sequoia
applemacos_sonoma
debiandebian_linux
debiandebian_linux
debianopenssh< openssh 1:9.2p1-2+deb12u5 (bookworm)openssh 1:9.2p1-2+deb12u5 (bookworm)
msrcazl3_openssh_9.8p1-3_on_azure_linux_3.0
msrcazl3_openssh_9.8p1-4_on_azure_linux_3.0
msrccbl2_openssh_8.9p1-7_on_cbl_mariner_2.0
msrccbl2_openssh_8.9p1-8_on_cbl_mariner_2.0
netappontap
openbsdopenssh
openbsdopenssh
openbsdopenssh
openbsdopenssh>= 0 < 1:8.4p1-5+deb11u41:8.4p1-5+deb11u4
openbsdopenssh>= 0 < 1:9.2p1-2+deb12u51:9.2p1-2+deb12u5
openbsdopenssh>= 0 < 1:9.9p2-11:9.9p2-1
openbsdopenssh>= 0 < 1:9.9p2-11:9.9p2-1
openbsdopenssh>= 0 < 1:8.2p1-4ubuntu0.121:8.2p1-4ubuntu0.12
openbsdopenssh>= 0 < 1:8.9p1-3ubuntu0.111:8.9p1-3ubuntu0.11
openbsdopenssh>= 0 < 1:9.6p1-3ubuntu13.81:9.6p1-3ubuntu13.8
openbsdopenssh>= 0 < 1:7.2p2-4ubuntu2.10+esm71:7.2p2-4ubuntu2.10+esm7
openbsdopenssh>= 0 < 1:7.6p1-4ubuntu0.7+esm41:7.6p1-4ubuntu0.7+esm4
openbsdopenssh6.9 – 9.8
paloaltopan-os
redhatenterprise_linux

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://www.qualys.com/2025/02/18/openssh-mitm-dos.txt
  • Attack vector involves presenting a large SSH key with excessive certificate extensions to exhaust client memory during host key verification; monitor for anomalously large SSH key/certificate exchanges
  • Exploit triggers an out-of-memory error during host key verification, causing the client to accept a rogue server key; monitor for SSH client connections to unexpected/new server fingerprints after OOM conditions
  • Affected OpenSSH client versions are 6.8p1 through 9.9p1; inventory and flag any SSH client binaries in this version range, especially on FreeBSD systems where VerifyHostKeyDNS was enabled by default until March 2023
  • FreeBSD systems are at elevated risk as VerifyHostKeyDNS was enabled by default from September 2013 until March 2023; prioritize scanning FreeBSD hosts for vulnerable OpenSSH client versions
  • ·Successful exploitation requires the attacker to first exhaust the client's memory resources, raising the practical attack complexity; however, this can be achieved by sending a large SSH key with excessive certificate extensions
  • ·The attack does not require an SSHFP DNS record to exist; absence of SSHFP records in DNS does not protect against exploitation

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_msrc6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.