CVE-2026-55654

Discovered by AISLEPUBLISHEDCWE-125

Description

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.

CVSS Base Scores

CVSS v3.1(Primary)
3.7

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersionStatus
Red HatRed Hat Enterprise Linux 100:9.9p1-25.el10_2unaffected
Red HatRed Hat Enterprise Linux 90:9.9p1-9.el9_8unaffected
Red HatRed Hat Hardened Images10.3p1-6.hum1unaffected
Red HatRed Hat Update Infrastructure 51786435483unaffected
Red HatRed Hat Update Infrastructure 51786533529unaffected
Red HatRed Hat Update Infrastructure 51787135742unaffected
Red HatRed Hat Update Infrastructure 51787241260unaffected
Red HatRed Hat Enterprise Linux 6——
Red HatRed Hat Enterprise Linux 7——
Red HatRed Hat Enterprise Linux 8——
Red HatRed Hat OpenShift Container Platform 4——

Credits

  • This issue was discovered by In partnership with Red Hat (Aisle.com).

References