Use-after-free in OpenSSH - CVE-2026-60002

 

Use-after-free in OpenSSH - CVE-2026-60002

Published: July 15, 2026


Vulnerability identifier: #VU137704
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-60002
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a client-side denial of service.

The vulnerability exists due to use-after-free in ssh(1) when processing a host key change during key reexchange. A remote attacker can change its host key during key reexchange to cause a client-side denial of service.


Affected software

OpenSSH
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
pam_ssh_agent_auth
openssh-server
openssh
openssh-askpass
openssh-cavs
openssh-clients
openssh-debuginfo
openssh-debugsource
openssh-keycat
openssh-ldap
openssh-help
openssh (Ubuntu package)
openssh-sk-dummy
openssh-doc
openssh-helpers-debuginfo
openssh-server-debuginfo
openssh-askpass-gnome-debuginfo
openssh-askpass-gnome
openssh-askpass-gnome-debugsource
openssh-cavs-debuginfo
openssh-common-debuginfo
openssh-server-config-disallow-rootlogin
openssh-helpers
openssh-clients-debuginfo
openssh-fips
openssh-common

How to mitigate CVE-2026-60002

Install security update from vendor's website.

OpenSSH - update to 10.4p1
pam_ssh_agent_auth - addressed in versions 0.10.3-9.42, 0.10.4-4.49, 0.10.4-5.20, 0.10.4-5.23
openssh-server - addressed in versions 8.2p1-42, 8.8p1-49, 9.6p1-20, 9.6p1-23
openssh - addressed in versions 8.2p1-42, 8.8p1-49, 9.6p1-20, 9.6p1-23
openssh-askpass - addressed in versions 8.2p1-42, 8.8p1-49, 9.6p1-20, 9.6p1-23
openssh-cavs - update to 8.2p1-42
openssh-clients - addressed in versions 8.2p1-42, 8.8p1-49, 9.6p1-20, 9.6p1-23
openssh-debuginfo - addressed in versions 8.2p1-42, 8.8p1-49, 9.6p1-20, 9.6p1-23
openssh-debugsource - addressed in versions 8.2p1-42, 8.8p1-49, 9.6p1-20, 9.6p1-23
openssh-keycat - addressed in versions 8.2p1-42, 8.8p1-49, 9.6p1-20, 9.6p1-23
openssh-ldap - update to 8.2p1-42
openssh-help - addressed in versions 8.2p1-42, 8.8p1-49, 9.6p1-20, 9.6p1-23
openssh (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.16, 1:9.6p1-3ubuntu13.18, 1:10.2p1-2ubuntu3.4
openssh-sk-dummy - update to 9.6p1-12
openssh-doc - update to 9.6p1-12
openssh-server - update to 9.6p1-12
openssh-keycat - update to 9.6p1-12
openssh-clients - update to 9.6p1-12
openssh-askpass - update to 9.6p1-12
openssh - update to 9.6p1-12
openssh - update to 9.6p1-150600.6.49.1
openssh-helpers-debuginfo - update to 9.6p1-150600.6.49.1
openssh-server-debuginfo - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debuginfo - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debugsource - update to 9.6p1-150600.6.49.1
openssh-cavs - update to 9.6p1-150600.6.49.1
openssh-cavs-debuginfo - update to 9.6p1-150600.6.49.1
openssh-common-debuginfo - update to 9.6p1-150600.6.49.1
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.49.1
openssh-clients - update to 9.6p1-150600.6.49.1
openssh-helpers - update to 9.6p1-150600.6.49.1
openssh-clients-debuginfo - update to 9.6p1-150600.6.49.1
openssh-fips - update to 9.6p1-150600.6.49.1
openssh-common - update to 9.6p1-150600.6.49.1
openssh-debuginfo - update to 9.6p1-150600.6.49.1
openssh-debugsource - update to 9.6p1-150600.6.49.1
openssh-server - update to 9.6p1-150600.6.49.1
openssh - addressed in versions 10.0p1-11.fc43, 10.2p1-13.fc44

External References

Related Security Bulletins