CVE-2026-106582

Published: October 9, 2026Last modified: October 9, 2026

Description

In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 "Crossing the Streams" findings.

Severity score breakdown

ParameterValue
Base score3.7
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopensshVulnerable (9.1_p1-r3)
25 LTSopensshVulnerable (10.0_p1-r7)
StreamopensshFixed (10.6_p1-r0)

References

ON THIS PAGE