CVE-2026-106555

Published: October 9, 2026Last modified: October 9, 2026

Description

In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.

Severity score breakdown

ParameterValue
Base score2.2
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredLOW
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopensshVulnerable (9.1_p1-r3)
25 LTSopensshVulnerable (10.0_p1-r7)
StreamopensshFixed (10.6_p1-r0)

References

ON THIS PAGE