Back

MEDIUM

openssh: the functions order_hostkeyalgs() and list_hostkey_types() leads to double-free vulnerability

Published Feb 3, 2023

Description

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 3, 2023
Updated May 28, 2026
Reserved Feb 3, 2023
CISA Vulnrichment
Updated Feb 27, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 3, 2023
ENISA EUVD
Assigner mitre
Published Feb 3, 2023
Updated May 28, 2026
Exploited since n/a
EUVD-2023-29115