CVE-2026-106584

Published: October 9, 2026Last modified: October 9, 2026

Description

In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations.

Severity score breakdown

ParameterValue
Base score2.5
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopensshVulnerable (9.1_p1-r3)
25 LTSopensshVulnerable (10.0_p1-r7)
StreamopensshFixed (10.6_p1-r0)

References

ON THIS PAGE