Input validation error in OpenSSH - CVE-2025-26466

 

Input validation error in OpenSSH - CVE-2025-26466

Published: February 18, 2025 / Updated: June 27, 2025


Vulnerability identifier: #VU104034
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-26466
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input related to SSH2_MSG_PING handling in sshd(8). A remote attacker can send specially crafted packets to the server and perform a denial of service (DoS) attack.


Affected software

OpenSSH
ArubaOS-CX (AOS-CX)
LANTIME Operating System Firmware (LTOS)
BIG-IP
QuTS hero
Precision 7920 XL Rack
Precision 7920 Rack
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
OpenBSD
IBM i
FreeBSD
macOS
Slackware Linux
Desktop Applications Module
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
openEuler
Fedora
Oracle Solaris
Fireware OS
FortiManager
FortiAnalyzer
FortiDDoS-F
FortiADC
APEX Cloud Platform for Red Hat OpenShift
FortiADC Manager
BIG-IP Next Central Manager
SmartFabric Manager
iDRAC9
pam_ssh_agent_auth
openssh-client (Ubuntu package)
openssh-server (Ubuntu package)
openssh
openssh-doc
openssh-sk-dummy
openssh-server
openssh-askpass
openssh-clients
openssh-keycat
openssh-help
openssh-debuginfo
openssh-debugsource
openssh-askpass-gnome-debuginfo
openssh-askpass-gnome-debugsource
openssh-askpass-gnome
openssh-helpers-debuginfo
openssh-common
openssh-cavs
openssh-common-debuginfo
openssh-fips
openssh-server-config-disallow-rootlogin
openssh-helpers
openssh-server-debuginfo
openssh-cavs-debuginfo
openssh-clients-debuginfo
APEX Cloud Platform for Microsoft Azure
CTPView
SmartFabric OS10
QNAP QTS

How to mitigate CVE-2025-26466

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

ArubaOS-CX (AOS-CX) - addressed in versions 10.10.1170, 10.13.1101, 10.14.1060, 10.15.1030, 10.16.1006
FortiManager - addressed in versions 7.2.11, 7.4.7, 7.6.3
FortiAnalyzer - addressed in versions 7.2.11, 7.4.7, 7.6.3
FortiDDoS-F - update to 7.0.5
LANTIME Operating System Firmware (LTOS) - update to 7.08.022
FortiADC Manager - update to 7.6.1
FortiADC - update to 7.6.2
macOS - addressed in versions 14.7.6 23H626, 15.5 24F74
QuTS hero - update to h5.2.4.3079 build 20250321
pam_ssh_agent_auth - update to 0.10.4-4.5
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
QNAP QTS - update to 5.2.4.3079 20250321
Precision 7920 XL Rack - update to 7.00.00.181
iDRAC9 - addressed in versions 7.00.00.181, 7.20.30.50
Precision 7920 Rack - update to 7.00.00.181
openssh-client (Ubuntu package) - addressed in versions 1:8.2p1-4ubuntu0.12, 1:8.9p1-3ubuntu0.11, 1:9.6p1-3ubuntu13.8, 1:9.7p1-7ubuntu4.2
openssh-server (Ubuntu package) - addressed in versions 1:8.2p1-4ubuntu0.12, 1:8.9p1-3ubuntu0.11, 1:9.6p1-3ubuntu13.8, 1:9.7p1-7ubuntu4.2
CTPView - update to 9.3R2
openssh - addressed in versions 9.6p1-2.fc40, 9.9p1-3.fc41
openssh-doc - update to 9.6p1-3
openssh-sk-dummy - update to 9.6p1-3
openssh-server - update to 9.6p1-3
openssh - update to 9.6p1-3
openssh-askpass - update to 9.6p1-3
openssh-clients - update to 9.6p1-3
openssh-keycat - update to 9.6p1-3
openssh-server - update to 9.6p1-5
openssh-help - update to 9.6p1-5
openssh-keycat - update to 9.6p1-5
openssh - update to 9.6p1-5
openssh-askpass - update to 9.6p1-5
openssh-clients - update to 9.6p1-5
openssh-debuginfo - update to 9.6p1-5
openssh-debugsource - update to 9.6p1-5
openssh-askpass-gnome-debuginfo - update to 9.6p1-150600.6.15.1
openssh-askpass-gnome-debugsource - update to 9.6p1-150600.6.15.1
openssh-askpass-gnome - update to 9.6p1-150600.6.15.1
openssh-debuginfo - update to 9.6p1-150600.6.15.2
openssh-debugsource - update to 9.6p1-150600.6.15.2
openssh-helpers-debuginfo - update to 9.6p1-150600.6.15.2
openssh-common - update to 9.6p1-150600.6.15.2
openssh - update to 9.6p1-150600.6.15.2
openssh-cavs - update to 9.6p1-150600.6.15.2
openssh-clients - update to 9.6p1-150600.6.15.2
openssh-common-debuginfo - update to 9.6p1-150600.6.15.2
openssh-fips - update to 9.6p1-150600.6.15.2
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.15.2
openssh-server - update to 9.6p1-150600.6.15.2
openssh-helpers - update to 9.6p1-150600.6.15.2
openssh-server-debuginfo - update to 9.6p1-150600.6.15.2
openssh-cavs-debuginfo - update to 9.6p1-150600.6.15.2
openssh-clients-debuginfo - update to 9.6p1-150600.6.15.2
openssh - update to 9.9p2
SmartFabric OS10 - update to 10.5.6.9
Oracle Solaris - addressed in versions 11.3 ESU 36.34, 11.4 SRU 80
Fireware OS - update to 12.11.3

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins