Man-in-the-Middle (MitM) attack in OpenSSH - CVE-2025-26465

 

Man-in-the-Middle (MitM) attack in OpenSSH - CVE-2025-26465

Published: February 18, 2025 / Updated: February 18, 2025


Vulnerability identifier: #VU104035
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-26465
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to incorrect processing of user-supplied data in ssh(1). A remote attacker can perform server impersonation when VerifyHostKeyDNS enabled.


Affected software

OpenSSH
IBM Security Verify Access
SUSE Linux Enterprise Server 15 SP3
Debian Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
Gentoo Linux
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
OpenBSD
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
FreeBSD
macOS
Slackware Linux
Basesystem Module
Desktop Applications Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Oracle Solaris
Netezza Appliance
Verify Identity Access Digital Credentials
APEX Cloud Platform for Microsoft Azure
Storage Resource Manager
SmartFabric OS10
Netcool Operations Insight
Red Hat Advanced Cluster Management for Kubernetes
APEX Cloud Platform for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
Dell Secure Connect Gateway
IBM Power Hardware Management Console (HMC)
PowerProtect Data Manager
LANTIME Operating System Firmware (LTOS)
QuTS hero
PowerScale OneFS
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
openssh-server (Ubuntu package)
openssh-client (Ubuntu package)
pam_ssh_agent_auth
openssh-debugsource
openssh-debuginfo
openssh-helpers-debuginfo
openssh-helpers
openssh-askpass-gnome
openssh-askpass-gnome-debuginfo
openssh
openssh-fips
openssh-keycat
openssh-clients
openssh-server
openssh-cavs
openssh-askpass
openssh-ldap
openssh (Red Hat package)
openssh-help
openssh8.4-fips
openssh8.4-helpers
openssh8.4-server
openssh8.4-clients-debuginfo
openssh8.4-common-debuginfo
openssh8.4-helpers-debuginfo
openssh8.4-server-debuginfo
openssh8.4
openssh8.4-common
openssh8.4-clients
openssh8.4-debugsource
openssh-cavs-debuginfo
openssh-common-debuginfo
openssh-server-debuginfo
openssh-clients-debuginfo
openssh-askpass-gnome-debugsource
openssh-common
openssh (Debian package)
openssh-doc
openssh-sk-dummy
openssh-server-config-disallow-rootlogin
Dell EMC NetWorker vProxy
SmartFabric Manager
Red Hat OpenShift GitOps
OpenShift Virtualization
Red Hat OpenShift Container Platform
Dell EMC Storage Monitoring and Reporting (SMR)
QNAP QTS
Red Hat Ceph Storage

How to mitigate CVE-2025-26465

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Netezza Appliance - update to 1.0.0.1
Netcool Operations Insight - update to 1.6.15
LANTIME Operating System Firmware (LTOS) - update to 7.08.022
macOS - addressed in versions 14.7.6 23H626, 15.5 24F74
Dell EMC NetWorker vProxy - addressed in versions 19.11.0.6, 19.12.0.2
openssh-server (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.12, 1:8.9p1-3ubuntu0.11, 1:9.6p1-3ubuntu13.8, 1:9.7p1-7ubuntu4.2
openssh-client (Ubuntu package) - addressed in versions Ubuntu Pro, 1:8.2p1-4ubuntu0.12, 1:8.9p1-3ubuntu0.11, 1:9.6p1-3ubuntu13.8, 1:9.7p1-7ubuntu4.2
QuTS hero - update to h5.2.4.3079 build 20250321
pam_ssh_agent_auth - update to 0.10.3-7.26.0.1
pam_ssh_agent_auth - addressed in versions 0.10.3-9.31, 0.10.4-4.5, 0.10.4-4.8, 0.10.4-4.34
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
Red Hat OpenShift GitOps - addressed in versions 1.15.3, 1.16.1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.13.3
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Red Hat OpenShift Dev Spaces - update to 3.21.0
OpenShift Virtualization - update to 4.16.7
Red Hat OpenShift Container Platform - addressed in versions 4.16.39, 4.17.26, 4.18.10, 4.19.0
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
QNAP QTS - update to 5.2.4.3079 20250321
Dell Secure Connect Gateway - update to 5.28.00.14
openssh-debugsource - addressed in versions 7.2p2-81.26.1, 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-debuginfo - addressed in versions 7.2p2-81.26.1, 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-helpers-debuginfo - addressed in versions 7.2p2-81.26.1, 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-helpers - addressed in versions 7.2p2-81.26.1, 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-askpass-gnome - addressed in versions 7.2p2-81.26.1, 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.1
openssh-askpass-gnome-debuginfo - addressed in versions 7.2p2-81.26.1, 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.1
openssh - addressed in versions 7.2p2-81.26.1, 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-fips - addressed in versions 7.2p2-81.26.1, 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-keycat - addressed in versions 8.0p1-26.0.1, 9.3p2-3
openssh-clients - addressed in versions 8.0p1-26.0.1, 9.3p2-3
openssh-server - addressed in versions 8.0p1-26.0.1, 9.3p2-3
openssh-cavs - update to 8.0p1-26.0.1
openssh-askpass - addressed in versions 8.0p1-26.0.1, 9.3p2-3
openssh - addressed in versions 8.0p1-26.0.1, 9.3p2-3
openssh-ldap - update to 8.0p1-26.0.1
openssh (Red Hat package) - addressed in versions 8.0p1-26.el8_10, 8.7p1-38.el9_4.5
Red Hat Ceph Storage - update to 8.1
openssh-help - addressed in versions 8.2p1-31, 8.8p1-34, 9.3p2-8, 9.6p1-5
openssh-server - addressed in versions 8.2p1-31, 8.8p1-34, 9.3p2-8, 9.6p1-5
openssh - addressed in versions 8.2p1-31, 8.8p1-34, 9.3p2-8, 9.6p1-5
openssh-askpass - addressed in versions 8.2p1-31, 8.8p1-34, 9.3p2-8, 9.6p1-5
openssh-cavs - update to 8.2p1-31
openssh-debuginfo - addressed in versions 8.2p1-31, 8.8p1-34, 9.3p2-8, 9.6p1-5
openssh-ldap - update to 8.2p1-31
openssh-keycat - addressed in versions 8.2p1-31, 8.8p1-34, 9.3p2-8, 9.6p1-5
openssh-debugsource - addressed in versions 8.2p1-31, 8.8p1-34, 9.3p2-8, 9.6p1-5
openssh-clients - addressed in versions 8.2p1-31, 8.8p1-34, 9.3p2-8, 9.6p1-5
openssh8.4-fips - update to 8.4p1-8.16.1
openssh8.4-helpers - update to 8.4p1-8.16.1
openssh8.4-server - update to 8.4p1-8.16.1
openssh8.4-clients-debuginfo - update to 8.4p1-8.16.1
openssh8.4-common-debuginfo - update to 8.4p1-8.16.1
openssh8.4-helpers-debuginfo - update to 8.4p1-8.16.1
openssh8.4-server-debuginfo - update to 8.4p1-8.16.1
openssh8.4 - update to 8.4p1-8.16.1
openssh8.4-common - update to 8.4p1-8.16.1
openssh8.4-clients - update to 8.4p1-8.16.1
openssh8.4-debugsource - update to 8.4p1-8.16.1
openssh-cavs-debuginfo - addressed in versions 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-common-debuginfo - addressed in versions 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-server-debuginfo - addressed in versions 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-cavs - addressed in versions 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-clients-debuginfo - addressed in versions 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-askpass-gnome-debugsource - addressed in versions 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.1
openssh-common - addressed in versions 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-server - addressed in versions 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh-clients - addressed in versions 8.4p1-150300.3.42.1, 9.6p1-150600.6.15.2
openssh (Debian package) - update to 1:9.2p1-2+deb12u5
openssh-doc - update to 9.3p2-3
openssh-sk-dummy - update to 9.3p2-3
openssh - addressed in versions 9.6p1-2.fc40, 9.9p1-3.fc41
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.15.2
openssh - update to 9.9p2
PowerScale OneFS - addressed in versions 9.10.1.3, 9.11.0.1
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1063.1, 11.1.1111.0
SmartFabric OS10 - update to 10.5.6.9
Oracle Solaris - addressed in versions 11.3 ESU 36.34, 11.4 SRU 80
PowerProtect Data Manager - update to 19.19.0-15

External References

Related Security Bulletins