openssh: Memory exhaustion due to unregistered KEXINIT handler after receiving message
Published Dec 9, 2016
7.5
HIGHCVSS 3.1
EPSS 29.46%
Description
The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that "OpenSSH upstream does not consider this as a security issue."
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
openssh
Not affected
Red Hat Enterprise Linux 6
openssh
Not affected
Red Hat Enterprise Linux 7
openssh
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | openssh | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssh | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssh | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Red Hat Product Security Team does not consider this issue to be a security flaw, for more information please refer to https://bugzilla.redhat.com/show_bug.cgi?id=1384860#c5
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 15, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (53 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 29.46% (0.29462) | 98.13th | v5 (v2026.06.15) |
| Jun 15, 2026 | 29.46% (0.29462) | 97.94th | v5 (v2026.06.15) |
| May 31, 2026 | 31.18% (0.31178) | 96.85th | v4 (v2025.03.14) |
| Mar 4, 2026 | 27.13% (0.27135) | 96.28th | v4 (v2025.03.14) |
| Mar 1, 2026 | 24.24% (0.24240) | 96.00th | v4 (v2025.03.14) |
| Feb 4, 2026 | 27.13% (0.27135) | 96.25th | v4 (v2025.03.14) |
| Feb 1, 2026 | 19.36% (0.19359) | 95.24th | v4 (v2025.03.14) |
| Jan 4, 2026 | 27.13% (0.27135) | 96.21th | v4 (v2025.03.14) |
| Jan 1, 2026 | 24.24% (0.24240) | 95.94th | v4 (v2025.03.14) |
| Dec 28, 2025 | 27.13% (0.27135) | 96.21th | v4 (v2025.03.14) |
| Dec 27, 2025 | 23.77% (0.23775) | 95.84th | v4 (v2025.03.14) |
| Dec 14, 2025 | 27.13% (0.27135) | 96.20th | v4 (v2025.03.14) |
| Dec 4, 2025 | 51.10% (0.51096) | 97.73th | v4 (v2025.03.14) |
| Dec 1, 2025 | 47.62% (0.47618) | 97.58th | v4 (v2025.03.14) |
| Nov 4, 2025 | 51.10% (0.51096) | 97.72th | v4 (v2025.03.14) |
| Nov 1, 2025 | 47.62% (0.47618) | 97.58th | v4 (v2025.03.14) |
| Oct 28, 2025 | 51.10% (0.51096) | 97.71th | v4 (v2025.03.14) |
| Oct 27, 2025 | 47.03% (0.47033) | 97.55th | v4 (v2025.03.14) |
| Oct 4, 2025 | 51.10% (0.51096) | 97.78th | v4 (v2025.03.14) |
| Sep 4, 2025 | 47.03% (0.47033) | 97.61th | v4 (v2025.03.14) |
| Sep 1, 2025 | 38.22% (0.38217) | 97.15th | v4 (v2025.03.14) |
| Aug 31, 2025 | 47.03% (0.47033) | 97.60th | v4 (v2025.03.14) |
| Aug 12, 2025 | 64.72% (0.64717) | 98.38th | v4 (v2025.03.14) |
| Aug 9, 2025 | 69.79% (0.69786) | 98.59th | v4 (v2025.03.14) |
| Aug 4, 2025 | 61.37% (0.61372) | 98.23th | v4 (v2025.03.14) |
| Aug 1, 2025 | 51.85% (0.51847) | 97.82th | v4 (v2025.03.14) |
| Jul 30, 2025 | 61.37% (0.61372) | 98.23th | v4 (v2025.03.14) |
| Jul 4, 2025 | 59.48% (0.59475) | 98.12th | v4 (v2025.03.14) |
| Jul 1, 2025 | 54.95% (0.54950) | 97.91th | v4 (v2025.03.14) |
| Jun 4, 2025 | 59.48% (0.59475) | 98.10th | v4 (v2025.03.14) |
| Jun 1, 2025 | 54.95% (0.54950) | 97.90th | v4 (v2025.03.14) |
| May 4, 2025 | 59.48% (0.59475) | 98.09th | v4 (v2025.03.14) |
| May 1, 2025 | 48.53% (0.48534) | 97.59th | v4 (v2025.03.14) |
| Mar 30, 2025 | 60.01% (0.60007) | 98.09th | v4 (v2025.03.14) |
| Mar 29, 2025 | 67.21% (0.67214) | 98.02th | v4 (v2025.03.14) |
| Mar 28, 2025 | 60.01% (0.60007) | 98.09th | v4 (v2025.03.14) |
| Mar 27, 2025 | 67.21% (0.67214) | 98.38th | v4 (v2025.03.14) |
| Mar 21, 2025 | 60.01% (0.60007) | 98.13th | v4 (v2025.03.14) |
| Mar 20, 2025 | 63.31% (0.63308) | 98.28th | v4 (v2025.03.14) |
| Mar 19, 2025 | 70.04% (0.70039) | 98.54th | v4 (v2025.03.14) |
| Mar 17, 2025 | 63.31% (0.63308) | 98.24th | v4 (v2025.03.14) |
| Dec 17, 2024 | 43.38% (0.43375) | 97.41th | v3 (v2023.03.01) |
| Aug 13, 2024 | 78.35% (0.78351) | 98.30th | v3 (v2023.03.01) |
| Aug 10, 2024 | 23.71% (0.23706) | 96.65th | v3 (v2023.03.01) |
| Mar 11, 2024 | 78.35% (0.78351) | 98.16th | v3 (v2023.03.01) |
| Nov 12, 2023 | 81.05% (0.81047) | 98.01th | v3 (v2023.03.01) |
| Sep 30, 2023 | 83.97% (0.83969) | 98.07th | v3 (v2023.03.01) |
| May 8, 2023 | 88.06% (0.88060) | 98.12th | v3 (v2023.03.01) |
| Mar 15, 2023 | 90.12% (0.90118) | 98.18th | v3 (v2023.03.01) |
| Mar 7, 2023 | 91.70% (0.91704) | 98.30th | v3 (v2023.03.01) |
| Mar 6, 2023 | 35.72% (0.35720) | 97.84th | v2 (v2022.01.01) |
| Dec 14, 2022 | 35.72% (0.35720) | 97.80th | v2 (v2022.01.01) |
| Feb 4, 2022 | 26.13% (0.26127) | 95.69th | v2 (v2022.01.01) |
References (16)
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/kex.c.diff?r1=1.126&r2=1.127&f=h Issue TrackingVendor Advisory
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/kex.c?rev=1.127&content-type=text/x-cvsweb-markup Issue TrackingVendor Advisory
- http://www.openwall.com/lists/oss-security/2016/10/19/3 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/10/20/1 mailing-listMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/93776 vdb-entryThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037057 vdb-entryThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2016-8858 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1384860 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://ftp.openbsd.org/pub/OpenBSD/patches/6.0/common/013_ssh_kexinit.patch.sig PatchVendor Advisory
- https://github.com/openssh/openssh-portable/commit/ec165c392ca54317dbe3064a8c200de6531e89ad Issue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-8858
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:33.openssh.asc vendor-advisoryThird Party Advisory
- https://security.gentoo.org/glsa/201612-18 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20180201-0001/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2016-8858
Change history (0)
No recorded changes yet.