CVE-2025-61985

Published: October 9, 2025Last modified: December 23, 2025

Description

ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

Severity score breakdown

ParameterValue
Base score3.6
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopensshFixed (9.1_p1-r11)
25 LTSopensshFixed (10.0_p1-r10)
StreamopensshFixed (10.1_p1-r0)
Hardened Containers23 LTSopensshFixed (9.1_p1-r11)
25 LTSopensshFixed (10.0_p1-r10)
StreamopensshFixed (10.1_p1-r0)

References

ON THIS PAGE