Logo
vulnerabilityCVE-2025-26465
Name
CVE-2025-26465
Source
NVD ( link)Debian ( link)
Description
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
openssh
Patched

Vulnerability Ratings#


6.8
CVSSv31
6.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
9.9p2
Not Affected
buildroot
master
10.3p1
Not Affected
openwrt
master
10.3_p1-r2
Not Affected
openwrt
openwrt-25.12
10.3_p1-r1
Not Affected
yocto
kirkstone
8.9p1
Patched
yocto
master
10.3p1
Not Affected

Resolved with patches#


openssh (yocto:kirkstone)

#
Title
Author
Resolve
1
upstream: Fix cases where error codes were not correctly set
"djm@openbsd.org" <djm@openbsd.org>
CVE-2025-26465

openssh (yocto:scarthgap)

#
Title
Author
Resolve
1
upstream: Fix cases where error codes were not correctly set
"djm@openbsd.org" <djm@openbsd.org>
CVE-2025-26465