Input validation error in OpenSSH - CVE-2025-26466
Published: February 18, 2025 / Updated: June 27, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input related to SSH2_MSG_PING handling in sshd(8). A remote attacker can send specially crafted packets to the server and perform a denial of service (DoS) attack.
Affected software
ArubaOS-CX (AOS-CX)
LANTIME Operating System Firmware (LTOS)
BIG-IP
QuTS hero
Precision 7920 XL Rack
Precision 7920 Rack
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
OpenBSD
IBM i
FreeBSD
macOS
Slackware Linux
Desktop Applications Module
Basesystem Module
openSUSE Leap
Ubuntu
Anolis OS
openEuler
Fedora
Oracle Solaris
Fireware OS
FortiManager
FortiAnalyzer
FortiDDoS-F
FortiADC
APEX Cloud Platform for Red Hat OpenShift
FortiADC Manager
BIG-IP Next Central Manager
SmartFabric Manager
iDRAC9
pam_ssh_agent_auth
openssh-client (Ubuntu package)
openssh-server (Ubuntu package)
openssh
openssh-doc
openssh-sk-dummy
openssh-server
openssh-askpass
openssh-clients
openssh-keycat
openssh-help
openssh-debuginfo
openssh-debugsource
openssh-askpass-gnome-debuginfo
openssh-askpass-gnome-debugsource
openssh-askpass-gnome
openssh-helpers-debuginfo
openssh-common
openssh-cavs
openssh-common-debuginfo
openssh-fips
openssh-server-config-disallow-rootlogin
openssh-helpers
openssh-server-debuginfo
openssh-cavs-debuginfo
openssh-clients-debuginfo
APEX Cloud Platform for Microsoft Azure
CTPView
SmartFabric OS10
QNAP QTS
How to mitigate CVE-2025-26466
FortiManager - addressed in versions 7.2.11, 7.4.7, 7.6.3
FortiAnalyzer - addressed in versions 7.2.11, 7.4.7, 7.6.3
FortiDDoS-F - update to 7.0.5
LANTIME Operating System Firmware (LTOS) - update to 7.08.022
FortiADC Manager - update to 7.6.1
FortiADC - update to 7.6.2
macOS - addressed in versions 14.7.6 23H626, 15.5 24F74
QuTS hero - update to h5.2.4.3079 build 20250321
pam_ssh_agent_auth - update to 0.10.4-4.5
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
QNAP QTS - update to 5.2.4.3079 20250321
Precision 7920 XL Rack - update to 7.00.00.181
iDRAC9 - addressed in versions 7.00.00.181, 7.20.30.50
Precision 7920 Rack - update to 7.00.00.181
openssh-client (Ubuntu package) - addressed in versions 1:8.2p1-4ubuntu0.12, 1:8.9p1-3ubuntu0.11, 1:9.6p1-3ubuntu13.8, 1:9.7p1-7ubuntu4.2
openssh-server (Ubuntu package) - addressed in versions 1:8.2p1-4ubuntu0.12, 1:8.9p1-3ubuntu0.11, 1:9.6p1-3ubuntu13.8, 1:9.7p1-7ubuntu4.2
CTPView - update to 9.3R2
openssh - addressed in versions 9.6p1-2.fc40, 9.9p1-3.fc41
openssh-doc - update to 9.6p1-3
openssh-sk-dummy - update to 9.6p1-3
openssh-server - update to 9.6p1-3
openssh - update to 9.6p1-3
openssh-askpass - update to 9.6p1-3
openssh-clients - update to 9.6p1-3
openssh-keycat - update to 9.6p1-3
openssh-server - update to 9.6p1-5
openssh-help - update to 9.6p1-5
openssh-keycat - update to 9.6p1-5
openssh - update to 9.6p1-5
openssh-askpass - update to 9.6p1-5
openssh-clients - update to 9.6p1-5
openssh-debuginfo - update to 9.6p1-5
openssh-debugsource - update to 9.6p1-5
openssh-askpass-gnome-debuginfo - update to 9.6p1-150600.6.15.1
openssh-askpass-gnome-debugsource - update to 9.6p1-150600.6.15.1
openssh-askpass-gnome - update to 9.6p1-150600.6.15.1
openssh-debuginfo - update to 9.6p1-150600.6.15.2
openssh-debugsource - update to 9.6p1-150600.6.15.2
openssh-helpers-debuginfo - update to 9.6p1-150600.6.15.2
openssh-common - update to 9.6p1-150600.6.15.2
openssh - update to 9.6p1-150600.6.15.2
openssh-cavs - update to 9.6p1-150600.6.15.2
openssh-clients - update to 9.6p1-150600.6.15.2
openssh-common-debuginfo - update to 9.6p1-150600.6.15.2
openssh-fips - update to 9.6p1-150600.6.15.2
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.15.2
openssh-server - update to 9.6p1-150600.6.15.2
openssh-helpers - update to 9.6p1-150600.6.15.2
openssh-server-debuginfo - update to 9.6p1-150600.6.15.2
openssh-cavs-debuginfo - update to 9.6p1-150600.6.15.2
openssh-clients-debuginfo - update to 9.6p1-150600.6.15.2
openssh - update to 9.9p2
SmartFabric OS10 - update to 10.5.6.9
Oracle Solaris - addressed in versions 11.3 ESU 36.34, 11.4 SRU 80
Fireware OS - update to 12.11.3
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenBSD sshd and ssh client
- Multiple vulnerabilities in OpenSSH
- Fedora 40 update for openssh
- Fedora 41 update for openssh
- Ubuntu update for openssh
- Slackware Linux update for openssh
- Gentoo update for OpenSSH
- SUSE update for openssh
- FreeBSD update for OpenSSH
- openEuler 24.03 LTS SP1 update for openssh
- Oracle Solaris update for third-party components
- OpenSSH denial of service in BIG-IP Next
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in Apple macOS Sonoma
- OpenSSH update for Fortinet products
- Meinberg LANTIME firmware update for third-party components (April 2025)
- Dell iDRAC9 update for OpenSSH
- Multiple vulnerabilities in Dell Precision Rack
- Dell Networking OS10 update for third-party components
- Dell SmartFabric Manager update for third-party components
- Multiple vulnerabilities in QNAP QTS and QuTS hero
- WatchGuard Fireware OS update for OpenSSH
- Juniper CTPView update for OpenSSH
- Multiple vulnerabilities in IBM i
- Anolis OS update for openssh
- Multiple vulnerabilities in Aruba Networking AOS-CX