Resource exhaustion in OpenSSH - CVE-2026-60000
Published: July 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource handling in sshd(8) when processing pre-authentication GSSAPI requests. A remote attacker can send crafted authentication attempts to cause a denial of service.
Only configurations with GSSAPIAuthentication enabled are affected.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
pam_ssh_agent_auth
openssh
openssh-askpass
openssh-cavs
openssh-clients
openssh-help
openssh-debuginfo
openssh-server
openssh-ldap
openssh-keycat
openssh-debugsource
openssh (Ubuntu package)
openssh-doc
openssh-sk-dummy
openssh-server-config-disallow-rootlogin
openssh-helpers-debuginfo
openssh-common
openssh-fips
openssh-clients-debuginfo
openssh-helpers
openssh-common-debuginfo
openssh-server-debuginfo
openssh-askpass-gnome-debuginfo
openssh-askpass-gnome
openssh-askpass-gnome-debugsource
openssh-cavs-debuginfo
How to mitigate CVE-2026-60000
pam_ssh_agent_auth - addressed in versions 0.10.3-9.42, 0.10.4-4.48, 0.10.4-5.19, 0.10.4-5.22
openssh - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-askpass - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-cavs - update to 8.2p1-42
openssh-clients - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-help - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-debuginfo - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-server - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-ldap - update to 8.2p1-42
openssh-keycat - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-debugsource - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.16, 1:9.6p1-3ubuntu13.18, 1:10.2p1-2ubuntu3.4
openssh-doc - update to 9.6p1-11
openssh-sk-dummy - update to 9.6p1-11
openssh-server - update to 9.6p1-11
openssh-keycat - update to 9.6p1-11
openssh-clients - update to 9.6p1-11
openssh-askpass - update to 9.6p1-11
openssh - update to 9.6p1-11
openssh-server - update to 9.6p1-150600.6.49.1
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.49.1
openssh-helpers-debuginfo - update to 9.6p1-150600.6.49.1
openssh-debugsource - update to 9.6p1-150600.6.49.1
openssh-debuginfo - update to 9.6p1-150600.6.49.1
openssh-common - update to 9.6p1-150600.6.49.1
openssh-fips - update to 9.6p1-150600.6.49.1
openssh-clients-debuginfo - update to 9.6p1-150600.6.49.1
openssh-helpers - update to 9.6p1-150600.6.49.1
openssh-clients - update to 9.6p1-150600.6.49.1
openssh-common-debuginfo - update to 9.6p1-150600.6.49.1
openssh-server-debuginfo - update to 9.6p1-150600.6.49.1
openssh - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debuginfo - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debugsource - update to 9.6p1-150600.6.49.1
openssh-cavs - update to 9.6p1-150600.6.49.1
openssh-cavs-debuginfo - update to 9.6p1-150600.6.49.1
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSH
- Ubuntu update for openssh
- Anolis OS update for openssh
- SUSE update for openssh
- openEuler 24.03 LTS SP3 update for openssh
- openEuler 24.03 LTS SP1 update for openssh
- openEuler 22.03 LTS SP4 update for openssh
- openEuler 20.03 LTS SP4 update for openssh
- openEuler 24.03 LTS SP4 update for openssh