OpenSSH: Client Information leak due to use of roaming connection feature
Published Jan 14, 2016
6.5
MEDIUMCVSS 3.1
EPSS 63.47%
Description
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
Affected products
No data.
Configuration 1
- 9.318
- 9.353
Running on/with
- 110
- 120
- 220
- 320
- 425
- 525
- 625
Configuration 3
- 5.0
- 5.0
- 5.1
- 5.1
- 5.2
- 5.2
- 5.3
- 5.3
- 5.4
- 5.4
- 5.5
- 5.5
- 5.6
- 5.6
- 5.7
- 5.7
- 5.8
- 5.8
- 5.9
- 5.9
- 6.0
- 6.0
- 6.1
- 6.1
- 6.2
- 6.2
- 6.2
- 6.3
- 6.3
- 6.4
- 6.4
- 6.5
- 6.5
- 6.6
- 6.6
- 6.7
- 6.7
- 6.8
- 6.8
- 6.9
- 6.9
- 7.0
- 7.0
- 7.1
- 7.1
Configuration 4
- ≤ 15.07
No data.
Red Hat Enterprise Linux 7
openssh-0:6.6.1p1-23.el7_2
Fixed · RHSA-2016:0043
Red Hat Enterprise Linux 4
openssh
Not affected
Red Hat Enterprise Linux 5
openssh
Not affected
Red Hat Enterprise Linux 6
openssh
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | openssh-0:6.6.1p1-23.el7_2 | Fixed | RHSA-2016:0043 |
| Red Hat Enterprise Linux 4 | openssh | Not affected | n/a |
| Red Hat Enterprise Linux 5 | openssh | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssh | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the version OpenSSH as shipped with Red Hat Enterprise Linux 4, 5 and 6. This issue affects the version of OpenSSH as shipped with Red Hat Enterprise Linux 7 in a non-default configuration. For more information please refer to https://access.redhat.com/articles/2123781
Red Hat mitigation
1. The vulnerable roaming code can be permanently disabled by adding the undocumented option "UseRoaming no" to the system-wide configuration file (usually /etc/ssh/ssh_config), or per-user configuration file (~/.ssh/config), or command-line (-o "UseRoaming no"). 2. If an OpenSSH client is disconnected from an SSH server that offers roaming, it prints "[connection suspended, press return to resume]" on stderr, and waits for '\n' or '\r' on stdin (and not on the controlling terminal) before it reconnects to the server; advanced users may become suspicious and press Control-C or Control-Z instead, thus avoiding the information leak. However, SSH commands that use the local stdin to transfer data to the remote server are bound to trigger this reconnection automatically (upon reading a '\n' or '\r' from stdin). Moreover, these non-interactive SSH commands (for example, backup scripts and cron jobs) commonly employ public-key authentication and are therefore perfect targets for this information leak.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
AV:N/AC:L/Au:S/C:P/I:N/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 29, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (41 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 63.47% (0.63468) | 99.19th | v5 (v2026.06.15) |
| Jun 15, 2026 | 63.47% (0.63468) | 99.10th | v5 (v2026.06.15) |
| Jun 7, 2026 | 77.40% (0.77397) | 99.00th | v4 (v2025.03.14) |
| May 30, 2026 | 71.66% (0.71658) | 98.76th | v4 (v2025.03.14) |
| Apr 9, 2026 | 67.20% (0.67203) | 98.56th | v4 (v2025.03.14) |
| Apr 4, 2026 | 70.41% (0.70410) | 98.68th | v4 (v2025.03.14) |
| Mar 4, 2026 | 67.20% (0.67203) | 98.53th | v4 (v2025.03.14) |
| Mar 1, 2026 | 80.56% (0.80560) | 99.12th | v4 (v2025.03.14) |
| Feb 4, 2026 | 67.20% (0.67203) | 98.51th | v4 (v2025.03.14) |
| Feb 1, 2026 | 80.56% (0.80560) | 99.11th | v4 (v2025.03.14) |
| Jan 4, 2026 | 67.20% (0.67203) | 98.50th | v4 (v2025.03.14) |
| Jan 1, 2026 | 77.35% (0.77349) | 98.95th | v4 (v2025.03.14) |
| Dec 4, 2025 | 67.20% (0.67203) | 98.48th | v4 (v2025.03.14) |
| Dec 2, 2025 | 77.35% (0.77349) | 98.93th | v4 (v2025.03.14) |
| Dec 1, 2025 | 80.56% (0.80560) | 99.09th | v4 (v2025.03.14) |
| Nov 4, 2025 | 67.20% (0.67203) | 98.48th | v4 (v2025.03.14) |
| Nov 1, 2025 | 80.56% (0.80560) | 99.09th | v4 (v2025.03.14) |
| Oct 4, 2025 | 67.20% (0.67203) | 98.50th | v4 (v2025.03.14) |
| Oct 1, 2025 | 80.56% (0.80560) | 99.10th | v4 (v2025.03.14) |
| Sep 4, 2025 | 66.39% (0.66391) | 98.48th | v4 (v2025.03.14) |
| Sep 1, 2025 | 79.76% (0.79763) | 99.07th | v4 (v2025.03.14) |
| Aug 4, 2025 | 66.39% (0.66391) | 98.45th | v4 (v2025.03.14) |
| Aug 1, 2025 | 79.76% (0.79763) | 99.05th | v4 (v2025.03.14) |
| Jul 4, 2025 | 67.20% (0.67203) | 98.45th | v4 (v2025.03.14) |
| Jul 1, 2025 | 80.56% (0.80560) | 99.08th | v4 (v2025.03.14) |
| Jun 4, 2025 | 67.20% (0.67203) | 98.44th | v4 (v2025.03.14) |
| Jun 1, 2025 | 80.56% (0.80560) | 99.08th | v4 (v2025.03.14) |
| May 4, 2025 | 67.20% (0.67203) | 98.43th | v4 (v2025.03.14) |
| May 1, 2025 | 80.56% (0.80560) | 99.07th | v4 (v2025.03.14) |
| Mar 30, 2025 | 67.20% (0.67203) | 98.44th | v4 (v2025.03.14) |
| Mar 29, 2025 | 75.13% (0.75133) | 98.54th | v4 (v2025.03.14) |
| Mar 17, 2025 | 67.20% (0.67203) | 98.43th | v4 (v2025.03.14) |
| Dec 21, 2024 | 2.90% (0.02904) | 90.56th | v3 (v2023.03.01) |
| Dec 17, 2024 | 4.05% (0.04052) | 92.00th | v3 (v2023.03.01) |
| Dec 12, 2024 | 0.69% (0.00695) | 80.88th | v3 (v2023.03.01) |
| Jun 14, 2024 | 0.24% (0.00238) | 62.03th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00238) | 60.02th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
References (40)
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10734 Third Party Advisory
- http://lists.apple.com/archives/security-announce/2016/Mar/msg00004.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176516.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175592.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175676.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176349.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00006.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00007.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00008.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00009.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00013.html vendor-advisoryMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00014.html vendor-advisoryMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/135273/Qualys-Security-Advisory-OpenSSH-Overflow-Leak.html Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/Jan/44 mailing-listMailing ListThird Party Advisory
- http://www.debian.org/security/2016/dsa-3446 vendor-advisoryThird Party Advisory
- http://www.openssh.com/txt/release-7.1p2 Vendor Advisory
- http://www.openwall.com/lists/oss-security/2016/01/14/7 mailing-listMailing ListThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html Third Party Advisory
- http://www.securityfocus.com/archive/1/537295/100/0/threaded mailing-listThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/80695 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1034671 vdb-entryThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2869-1 vendor-advisoryThird Party Advisory
- https://access.redhat.com/articles/2123781
- https://access.redhat.com/security/cve/CVE-2016-0777 Vendor Advisory
- https://blogs.sophos.com/2016/02/17/utm-up2date-9-354-released/ Third Party Advisory
- https://blogs.sophos.com/2016/02/29/utm-up2date-9-319-released/ Third Party Advisory
- https://bto.bluecoat.com/security-advisory/sa109 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1298032 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05247375 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680 Third Party Advisory
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-0777
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:07.openssh.asc vendor-advisoryThird Party Advisory
- https://security.gentoo.org/glsa/201601-01 vendor-advisoryThird Party Advisory
- https://support.apple.com/HT206167 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2016-0777
- https://www.qualys.com/2016/01/14/cve-2016-0777-cve-2016-0778/openssh-cve-2016-0777-cve-2016-0778.txt
Change history (0)
No recorded changes yet.