Back

HIGH

openssh: Out of sequence NEWKEYS message can allow remote attacker to cause denial of service

Published Jan 21, 2018

Description

sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.

Affected products

Remediation

Red Hat statement

This issue affects the versions of openssh as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7 (versions 7.3 and earlier). For Red Hat Enterprise Linux 7 (versions 7.4 and later), this issue was fixed by the Security Advisory RHSA-2017:2029. For Red Hat Enterprise Linux 6, Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 21, 2018
Updated Apr 29, 2026
Reserved Jan 21, 2018
CISA Vulnrichment
Updated Apr 28, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 24, 2018