CVE-2026-35387

Published: April 4, 2026Last modified: April 17, 2026

Description

OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.

Severity score breakdown

ParameterValue
Base score6.5
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopensshUnknown (9.1_p1-r3)
25 LTSopensshFixed (10.3_p1-r0)
StreamopensshFixed (10.3_p1-r0)
Hardened Containers23 LTSopensshUnknown (9.1_p1-r3)
25 LTSopensshFixed (10.3_p1-r0)
StreamopensshFixed (10.3_p1-r0)

References

ON THIS PAGE