CVE-2025-26465
published 2025-02-18CVE-2025-26465: A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine…
PriorityP345medium6.8CVSS 3.1
AVNACHPRNUIRSUCHIHAN
EPSS
7.45%
93.8th percentile
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssh | < openssh 1:9.2p1-2+deb12u5 (bookworm) | openssh 1:9.2p1-2+deb12u5 (bookworm) |
| msrc | azl3_openssh_9.8p1-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_openssh_9.8p1-4_on_azure_linux_3.0 | — | — |
| msrc | cbl2_openssh_8.9p1-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_openssh_8.9p1-8_on_cbl_mariner_2.0 | — | — |
| netapp | ontap | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | — | — |
| openbsd | openssh | >= 0 < 1:8.4p1-5+deb11u4 | 1:8.4p1-5+deb11u4 |
| openbsd | openssh | >= 0 < 1:9.2p1-2+deb12u5 | 1:9.2p1-2+deb12u5 |
| openbsd | openssh | >= 0 < 1:9.9p2-1 | 1:9.9p2-1 |
| openbsd | openssh | >= 0 < 1:9.9p2-1 | 1:9.9p2-1 |
| openbsd | openssh | >= 0 < 1:8.2p1-4ubuntu0.12 | 1:8.2p1-4ubuntu0.12 |
| openbsd | openssh | >= 0 < 1:8.9p1-3ubuntu0.11 | 1:8.9p1-3ubuntu0.11 |
| openbsd | openssh | >= 0 < 1:9.6p1-3ubuntu13.8 | 1:9.6p1-3ubuntu13.8 |
| openbsd | openssh | >= 0 < 1:7.2p2-4ubuntu2.10+esm7 | 1:7.2p2-4ubuntu2.10+esm7 |
| openbsd | openssh | >= 0 < 1:7.6p1-4ubuntu0.7+esm4 | 1:7.6p1-4ubuntu0.7+esm4 |
| openbsd | openssh | 6.9 – 9.8 | — |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector involves presenting a large SSH key with excessive certificate extensions to exhaust client memory during host key verification; monitor for anomalously large SSH key/certificate exchanges ↗
- →Exploit triggers an out-of-memory error during host key verification, causing the client to accept a rogue server key; monitor for SSH client connections to unexpected/new server fingerprints after OOM conditions ↗
- →Affected OpenSSH client versions are 6.8p1 through 9.9p1; inventory and flag any SSH client binaries in this version range, especially on FreeBSD systems where VerifyHostKeyDNS was enabled by default until March 2023 ↗
- →FreeBSD systems are at elevated risk as VerifyHostKeyDNS was enabled by default from September 2013 until March 2023; prioritize scanning FreeBSD hosts for vulnerable OpenSSH client versions ↗
- ·Successful exploitation requires the attacker to first exhaust the client's memory resources, raising the practical attack complexity; however, this can be achieved by sending a large SSH key with excessive certificate extensions ↗
- ·The attack does not require an SSHFP DNS record to exist; absence of SSHFP records in DNS does not protect against exploitation ↗
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_msrc6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
Apple
CVE-2025-26465: macOS Sonoma 14.7.6
vendor_apple·2025-05-12·CVSS 6.8
CVE-2025-26465 [MEDIUM] CVE-2025-26465: macOS Sonoma 14.7.6
Apple Security Update: About the security content of macOS Sonoma 14.7.6
Product: macOS Sonoma
Version: 14.7.6
CVE: CVE-2025-26465
Component: CVE-2025-26465
Apple
CVE-2025-26465: macOS Sequoia 15.5
vendor_apple·2025-05-12·CVSS 6.8
CVE-2025-26465 [MEDIUM] CVE-2025-26465: macOS Sequoia 15.5
Apple Security Update: About the security content of macOS Sequoia 15.5
Product: macOS Sequoia
Version: 15.5
CVE: CVE-2025-26465
Component: CVE-2025-26465
BSD
FreeBSD-SA-25:05.openssh: Multiple vulnerabilities in OpenSSH
bsd_advisories·2025-02-21·CVSS 6.8
CVE-2025-26465 [MEDIUM] FreeBSD-SA-25:05.openssh: Multiple vulnerabilities in OpenSSH
FreeBSD-SA-25:05.openssh Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in OpenSSH
Category: contrib
Module: openssh
Announced: 2025-02-21
Credits: Qualys Security Advisory team
Affects: All supported versions of FreeBSD.
Corrected: 2025-02-19 14:54:37 UTC (stable/14, 14.2-STABLE)
2025-02-21 02:56:26 UTC (releng/14.2, 14.2-RELEASE-p2)
2025-02-21 02:56:40 UTC (releng/14.1, 14.1-RELEASE-p8)
2025-02-19 16:05:16 UTC (stable/13, 13.5-STABLE)
2025-02-20 18:00:47 UTC (releng/13.5, 13.5-BETA3)
2025-02-21 02:56:50 UTC (releng/13.4, 13.4-RELEASE-p4)
CVE Name: CVE-2025-26465, CVE-2025-26466
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
Op
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2025-02-18·CVSS 6.8
CVE-2025-26465 [MEDIUM] OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
It was discovered that the OpenSSH client incorrectly handled the
non-default VerifyHostKeyDNS option. If that option were enabled, an
attacker could possibly impersonate a server by completely bypassing the
server identity check. (CVE-2025-26465)
It was discovered that OpenSSH incorrectly handled the transport-level ping
facility. A remote attacker could possibly use this issue to cause OpenSSH
clients and servers to consume resources, leading to a denial of service.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2025-26466)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
OpenSSH vulnerability
vendor_ubuntu·2025-02-18·CVSS 6.8
CVE-2025-26465 [MEDIUM] OpenSSH vulnerability
Title: OpenSSH vulnerability
Summary: OpenSSH could be made to bypass the server identity check.
USN-7270-1 fixed a vulnerability in OpenSSH. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that the OpenSSH client incorrectly handled the
non-default VerifyHostKeyDNS option. If that option were enabled, an
attacker could possibly impersonate a server by completely bypassing the
server identity check. (CVE-2025-26465)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openssh: Machine-in-the-middle attack if VerifyHostKeyDNS is enabled
vendor_redhat·2025-02-17·CVSS 6.8
CVE-2025-26465 [MEDIUM] CWE-390 openssh: Machine-in-the-middle attack if VerifyHostKeyDNS is enabled
openssh: Machine-in-the-middle attack if VerifyHostKeyDNS is enabled
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifyin
Palo Alto
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2025-02-12·CVSS 7.1
CVE-2015-5312 [HIGH] PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
T he Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2015-5312, CVE-2016-4607, CVE-2016-4608, CVE-2016-4609, CVE-2016-4738, CVE-2018-1111, CVE-2018-14634, CVE-2018-18653, CVE-2019-0145, CVE-2019-8331, CVE-2020-0599, CVE-2020-14343, CVE-2020-14779, CVE-2020-27844, CVE-2020-29569, CVE-2021-21315, CVE-2021-27853, CVE-2021-27854, CVE-2021-27861, CVE-2021-27862, CVE-2021-3618, CVE-2021-3711, CVE-2022-2097, CVE-2022-22816, CVE-2022-40303, CVE-2022-41723, CVE-2022-41741, CVE-2022-41742, CVE-2023-3247, CVE-2023-38408, CVE-2023-44466, CVE-2023-50781, CVE-2023-50782, CVE-2024-12084, CV
Microsoft
Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled
vendor_msrc·2025-02-11·CVSS 6.8
CVE-2025-26465 [MEDIUM] CWE-390 Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled
Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference
Debian
CVE-2025-26465: openssh - A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled...
vendor_debian·2025·CVSS 6.8
CVE-2025-26465 [MEDIUM] CVE-2025-26465: openssh - A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled...
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
Scope: local
bookworm: resolved (fixed in 1:9.2p1-2+deb12u5)
bullseye: resolved (fixed in 1:8.4p1-5+deb11u4)
forky: resolved (fixed in 1:9.9p2-1)
sid: resolved (fixed in 1:9.9p2-1)
trixie: resolved (fixed in 1:9.9p2-1)
GHSA
GHSA-jrwv-mv4h-7rrq: A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled
ghsa_unreviewed·2025-02-18
CVE-2025-26465 [MEDIUM] CWE-390 GHSA-jrwv-mv4h-7rrq: A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
OSV
openssh vulnerability
osv·2025-02-18·CVSS 6.8
CVE-2025-26465 [MEDIUM] openssh vulnerability
openssh vulnerability
USN-7270-1 fixed a vulnerability in OpenSSH. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that the OpenSSH client incorrectly handled the
non-default VerifyHostKeyDNS option. If that option were enabled, an
attacker could possibly impersonate a server by completely bypassing the
server identity check. (CVE-2025-26465)
OSV
openssh vulnerabilities
osv·2025-02-18·CVSS 6.8
CVE-2025-26465 [MEDIUM] openssh vulnerabilities
openssh vulnerabilities
It was discovered that the OpenSSH client incorrectly handled the
non-default VerifyHostKeyDNS option. If that option were enabled, an
attacker could possibly impersonate a server by completely bypassing the
server identity check. (CVE-2025-26465)
It was discovered that OpenSSH incorrectly handled the transport-level ping
facility. A remote attacker could possibly use this issue to cause OpenSSH
clients and servers to consume resources, leading to a denial of service.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2025-26466)
OSV
CVE-2025-26465: A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled
osv·2025-02-18·CVSS 6.8
CVE-2025-26465 [MEDIUM] CVE-2025-26465: A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
No detection rules found.
No public exploits indexed.
Qualys
Two Pwnie Awards, One Crucial Lesson: What Our OpenSSH Research Reveals About Cyber Defense in 2025
blogs_qualys·2025-08-12·CVSS 8.1
CVE-2024-6387 [HIGH] Two Pwnie Awards, One Crucial Lesson: What Our OpenSSH Research Reveals About Cyber Defense in 2025
## Table of Contents
Why these two matter
Key Takeaways for Security Leaders: What Patching Really Looks Like
How Qualys Customers Achieve Same-Day Closes with TruRisk
We’re honored that the Pwnie Awards recognized the Qualys Threat Research Unit (TRU) with two wins at Black Hat/DEF CON this year—Best RCE for regreSSHion (CVE-2024-6387) and Epic Achievement for our multi-year work uncovering issues in OpenSSH, including CVE-2025-26465. Awards are nice; what matters is what the research means for defenders.
The Pwnie Awards, held annually at Black Hat and DEF CON, celebrate groundbreaking (and sometimes infamous) achievements in cybersecurity. Winning two in one year—especially for high-impact vulnerabilities in a staple like OpenSSH—is a massive validation for our TRU team. It undersc
Qualys
Two Pwnie Awards, One Crucial Lesson: What Our OpenSSH Research Reveals About Cyber Defense in 2025 | Qualys
blogs_qualys·2025-08-12·CVSS 8.1
CVE-2024-6387 [HIGH] Two Pwnie Awards, One Crucial Lesson: What Our OpenSSH Research Reveals About Cyber Defense in 2025 | Qualys
#### Table of Contents
- Why these two matter
- Key Takeaways for Security Leaders: What Patching Really Looks Like
- How Qualys Customers Achieve Same-Day Closes with TruRisk
We’re honored that the Pwnie Awards recognized the Qualys Threat Research Unit (TRU) with two wins at Black Hat/DEF CON this year—Best RCE for regreSSHion (CVE-2024-6387) and Epic Achievement for our multi-year work uncovering issues in OpenSSH, including CVE-2025-26465. Awards are nice; what matters is what the research means for defenders.
The Pwnie Awards, held annually at Black Hat and DEF CON, celebrate groundbreaking (and sometimes infamous) achievements in cybersecurity. Winning two in one year—especially for high-impact vulnerabilities in a staple like OpenSSH—is a massive validation for our TRU team. It u
Bleepingcomputer
Microsoft testing fix for Windows 11 bug breaking SSH connections
blogs_bleepingcomputer·2025-02-20
Microsoft testing fix for Windows 11 bug breaking SSH connections
## Microsoft testing fix for Windows 11 bug breaking SSH connections
## Sergiu Gatlan
Microsoft is now testing a fix for a longstanding known issue that is breaking SSH connections on some Windows 11 22H2 and 23H2 systems.
On Tuesday, Microsoft started rolling Windows 11 Build 26100.3321 (KB5052093) Insiders in the Release Preview Channel on Windows 11 24H2 (Build 26100) with a fix for this bug.
When it first acknowledged the issue in November, the company explained it affects a "limited number" of devices running Windows 11 enterprise, IOT, and education editions. However, Redmond is also investigating whether consumer customers using Windows 11 Home or Pro editions are affected.
"Following the installation of the October 2024 security update, some customers report that the OpenSSH (
Qualys
Qualys TRU Uncovers OpenSSH Vulnerabilities CVE‑2025‑26465 & CVE‑2025‑26466 | Qualys
blogs_qualys·2025-02-18·CVSS 6.8
CVE-2025-26465 [MEDIUM] Qualys TRU Uncovers OpenSSH Vulnerabilities CVE‑2025‑26465 & CVE‑2025‑26466 | Qualys
#### Table of Contents
- About OpenSSH: Securing Enterprise Communications and Infrastructure
- Affected OpenSSH versions:
- Potential Impact
- Technical Details
- Qualys QID Coverage
- Discover Vulnerable Assets Using Qualys CyberSecurity Asset Management (CSAM)
- Enhance Your Security Posture with Qualys Vulnerability Management, Detection, and Response (VMDR)
- Automatically Patch these vulnerabilities With Qualys Patch Management
- Detect and remediate CVE-2025-26466 and CVE-2025-26465 with Qualys TotalCloud Container Security
- Conclusion
The Qualys Threat Research Unit (TRU) has identified two vulnerabilities in OpenSSH. The first, tracked as CVE-2025-26465, allows an active machine-in-the-middle attack on the OpenSSH client when the VerifyHostKeyDNS option is enabled. The second,
Qualys
Qualys TRU Discovers Two Vulnerabilities in OpenSSH: CVE-2025-26465 & CVE-2025-26466
blogs_qualys·2025-02-18·CVSS 6.8
CVE-2025-26466 [MEDIUM] Qualys TRU Discovers Two Vulnerabilities in OpenSSH: CVE-2025-26465 & CVE-2025-26466
## Table of Contents
About OpenSSH: Securing Enterprise Communications and Infrastructure
Affected OpenSSH versions:
Potential Impact
Technical Details
Qualys QID Coverage
Discover Vulnerable Assets Using Qualys CyberSecurity Asset Management (CSAM)
Enhance Your Security Posture with Qualys Vulnerability Management, Detection, and Response (VMDR)
Automatically Patch these vulnerabilities With Qualys Patch Management
Detect and remediate CVE-2025-26466 and CVE-2025-26465 with Qualys TotalCloud Container Security
Conclusion
The Qualys Threat Research Unit (TRU) has identified two vulnerabilities in OpenSSH. The first, tracked as CVE-2025-26465, allows an active machine-in-the-middle attack on the OpenSSH client when the VerifyHostKeyDNS option is enabled. The second, CVE-2025-2646
Bleepingcomputer
New OpenSSH flaws expose SSH servers to MiTM and DoS attacks
blogs_bleepingcomputer·2025-02-18·CVSS 6.8
[MEDIUM] New OpenSSH flaws expose SSH servers to MiTM and DoS attacks
## New OpenSSH flaws expose SSH servers to MiTM and DoS attacks
## Bill Toulas
OpenSSH has released security updates addressing two vulnerabilities, a man-in-the-middle (MitM) and a denial of service flaw, with one of the flaws introduced over a decade ago.
Qualys discovered both vulnerabilities and demonstrated their exploitability to OpenSSH's maintainers.
OpenSSH (Open Secure Shell) is a free, open-source implementation of the SSH (Secure Shell) protocol, which provides encrypted communication for secure remote access, file transfers, and tunneling over untrusted networks.
It is one of the most widely used tools in the world, with high levels of adoption across Linux and Unix-based (BSD, macOS) systems found in enterprise environments, IT, DevOps, cloud computing, and cybersecurity
Bugzilla
CVE-2025-26465 openssh: Machine-in-the-middle attack if VerifyHostKeyDNS is enabled
bugzilla·2025-02-10·CVSS 6.8
CVE-2025-26465 [MEDIUM] CVE-2025-26465 openssh: Machine-in-the-middle attack if VerifyHostKeyDNS is enabled
CVE-2025-26465 openssh: Machine-in-the-middle attack if VerifyHostKeyDNS is enabled
The OpenSSH client is vulnerable to an active machine-in-the-middle attack if the VerifyHostKeyDNS option is enabled (it is disabled by default): when a vulnerable client connects to a server, an active machine-in-the-middle can impersonate the server by completely bypassing the client's checks of the server's identity.
Discussion:
Making it Public as https://seclists.org/oss-sec/2025/q1/144
---
I am reading that correctly on https://access.redhat.com/security/cve/CVE-2025-26465 -- there is no fix planned for rhel8 because it's a non-default config+moderate rating?
---
Regarding the CVE link mentioned below, the OpenSSH client must have the VerifyHostKeyDNS option enabled, which is disabled by defaul
https://access.redhat.com/errata/RHSA-2025:16823https://access.redhat.com/errata/RHSA-2025:3837https://access.redhat.com/errata/RHSA-2025:6993https://access.redhat.com/errata/RHSA-2025:8385https://access.redhat.com/security/cve/CVE-2025-26465https://access.redhat.com/solutions/7109879https://bugzilla.redhat.com/show_bug.cgi?id=2344780https://seclists.org/oss-sec/2025/q1/144http://seclists.org/fulldisclosure/2025/Feb/18http://seclists.org/fulldisclosure/2025/May/7http://seclists.org/fulldisclosure/2025/May/8https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-discovers-two-vulnerabilities-in-openssh-cve-2025-26465-cve-2025-26466https://bugzilla.suse.com/show_bug.cgi?id=1237040https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sighttps://lists.debian.org/debian-lts-announce/2025/02/msg00020.htmlhttps://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.htmlhttps://security-tracker.debian.org/tracker/CVE-2025-26465https://security.netapp.com/advisory/ntap-20250228-0003/https://ubuntu.com/security/CVE-2025-26465https://www.openssh.com/releasenotes.html#9.9p2https://www.openwall.com/lists/oss-security/2025/02/18/1https://www.openwall.com/lists/oss-security/2025/02/18/4https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-opensshhttps://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-opensshhttps://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-585531.htmlhttps://seclists.org/oss-sec/2025/q1/144
2025-02-18
Published