Back

MEDIUM

openssh: Leak of host private key material to privilege-separated child process via realloc()

Published Jan 5, 2017

Description

authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.

Affected products

Remediation

Red Hat statement

It seems that this flaw is not practically exploitable, the leak of host private key material to the privilege-separated child processes is theoretical. No such leak was observed in practice for normal-sized keys, nor does a leak to the child processes directly expose key material to unprivileged users. Because of the this restriction for successful exploitation, this issue has been rated as having Low security impact. A future update may address this flaw.

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 5, 2017
Updated May 29, 2026
Reserved Dec 19, 2016
CISA Vulnrichment
Updated May 29, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 19, 2016