Use-after-free in OpenSSH - CVE-2026-73282

 

Use-after-free in OpenSSH - CVE-2026-73282

Published: September 3, 2026


Vulnerability identifier: #VU146882
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-73282
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to use-after-free in the ssh client remote forwarding handling when a remote forwarding is added via the local session multiplexing socket while a remote forwarding open request is pending with the server. A remote user can trigger this race condition to cause a denial of service.

Exploitation requires access to the local session multiplexing socket while a remote forwarding open request is pending.


Affected software

OpenSSH
Ubuntu
openssh (Ubuntu package)

How to mitigate CVE-2026-73282

Install security update from vendor's website.

OpenSSH - update to 10.5p1
openssh (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.17, 1:9.6p1-3ubuntu13.19, 1:10.2p1-2ubuntu3.6

External References

Related Security Bulletins