OpenSSH 9.9p2 : Fix CVE-2025-26465 and Fix CVE-2025-26466

Discussion in 'privacy technology' started by FanJ, Feb 18, 2025.

  1. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,920
    OpenSSH 9.9p2 released 2025-02-18

    Release Notes:
    https://www.openssh.com/releasenotes.html

    This release fixes two security bugs:
    Quoting:

    Fix CVE-2025-26465 - ssh(1) in OpenSSH versions 6.8p1 to 9.9p1
    (inclusive) contained a logic error that allowed an on-path
    attacker (a.k.a MITM) to impersonate any server when the
    VerifyHostKeyDNS option is enabled. This option is off by default.

    Fix CVE-2025-26466 - sshd(8) in OpenSSH versions 9.5p1 to 9.9p1
    (inclusive) is vulnerable to a memory/CPU denial-of-service related
    to the handling of SSH2_MSG_PING packets. This condition may be
    mitigated using the existing PerSourcePenalties feature.

    Read there more and at the links given there!
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.