openssh: the functions order_hostkeyalgs() and list_hostkey_types() leads to double-free vulnerability
Published Feb 3, 2023
6.5
MEDIUMCVSS 3.1
EPSS 89.69%
Description
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."
Affected products
No data.
Configuration 2
- 37
- 38
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
No data.
Red Hat Enterprise Linux 9
openssh-0:8.7p1-29.el9_2
Fixed · RHSA-2023:2645
Red Hat Enterprise Linux 9
openssh-0:8.7p1-29.el9_2
Fixed · RHSA-2023:2645
Red Hat Enterprise Linux 6
openssh
Not affected
Red Hat Enterprise Linux 7
openssh
Not affected
Red Hat Enterprise Linux 8
openssh
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | openssh-0:8.7p1-29.el9_2 | Fixed | RHSA-2023:2645 |
| Red Hat Enterprise Linux 9 | openssh-0:8.7p1-29.el9_2 | Fixed | RHSA-2023:2645 |
| Red Hat Enterprise Linux 6 | openssh | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssh | Not affected | n/a |
| Red Hat Enterprise Linux 8 | openssh | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (21)
- http://www.openwall.com/lists/oss-security/2023/02/13/1 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/02/22/1 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/02/22/2 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/02/23/3 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/03/06/1 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/03/09/2 mailing-listMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-25136 Vendor Advisory
- https://bugzilla.mindrot.org/show_bug.cgi?id=3522 ExploitIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2167636 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-29115 Advisory
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/017_sshd.patch.sig PatchVendor Advisory
- https://github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946 PatchThird Party Advisory
- https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/ ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JGAUIXJ3TEKCRKVWFQ6GDAGQFTIIGQQP/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7LKQDFZWKYHQ65TBSH2X2HJQ4V2THS3/ vendor-advisory
- https://news.ycombinator.com/item?id=34711565 Issue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-25136
- https://security.gentoo.org/glsa/202307-01 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20230309-0003/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-25136
- https://www.openwall.com/lists/oss-security/2023/02/02/2 ExploitMailing ListThird Party Advisory
Change history (0)
No recorded changes yet.