Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-25136

Published: October 18, 2023Last modified: October 18, 2023

Description

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."

Severity score breakdown

ParameterValue
Base score6.5
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactLOW
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopensshFixed (9.1_p1-r7)
StreamopensshNot affected (9.4_p1-r0)

References

ON THIS PAGE