openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client
Published Aug 11, 2026
5.6
MEDIUMCVSS 3.1
EPSS 0.16%
Description
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
Affected products
-
- Version 0StatusaffectedConstraints<10.5
- Version
No data.
Red Hat Enterprise Linux 10
openssh-0:9.9p1-27.el10_2
Fixed · RHSA-2026:69129
Red Hat Enterprise Linux 8
openssh-0:8.0p1-33.el8_10
Fixed · RHSA-2026:69266
Red Hat Enterprise Linux 8
openssh-0:8.0p1-33.el8_10
Fixed · RHSA-2026:69266
Red Hat Enterprise Linux 9
openssh-0:9.9p1-11.el9_8
Fixed · RHSA-2026:69130
Red Hat Enterprise Linux 9
openssh-0:9.9p1-11.el9_8
Fixed · RHSA-2026:69130
Red Hat Enterprise Linux 6
openssh
Fix deferred
Red Hat Enterprise Linux 7
openssh
Fix deferred
Red Hat Hardened Images
openssh
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | openssh-0:9.9p1-27.el10_2 | Fixed | RHSA-2026:69129 |
| Red Hat Enterprise Linux 8 | openssh-0:8.0p1-33.el8_10 | Fixed | RHSA-2026:69266 |
| Red Hat Enterprise Linux 8 | openssh-0:8.0p1-33.el8_10 | Fixed | RHSA-2026:69266 |
| Red Hat Enterprise Linux 9 | openssh-0:9.9p1-11.el9_8 | Fixed | RHSA-2026:69130 |
| Red Hat Enterprise Linux 9 | openssh-0:9.9p1-11.el9_8 | Fixed | RHSA-2026:69130 |
| Red Hat Enterprise Linux 6 | openssh | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | openssh | Fix deferred | n/a |
| Red Hat Hardened Images | openssh | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A use-after-free flaw exists in OpenSSH's ssh client during concurrent remote-forwarding processing. When adding a remote forward via the local session multiplexing socket while a server remote-forward open request is pending, realloc data management fails, freeing memory that remains actively referenced. A remote attacker with high attack complexity can exploit this timing window to corrupt process memory, posing a low impact to confidentiality, integrity, and availability.
Red Hat mitigation
Avoid issuing dynamic remote-forwarding commands over active SSH multiplexing connections, or disable socket multiplexing by setting ControlMaster no in ~/.ssh/config.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-73282 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2514328 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56891 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73282
- https://www.cve.org/CVERecord?id=CVE-2026-73282
- https://www.openssh.org/releasenotes.html#10.5 ProductRelease Notes
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-73282 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2514328 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56891 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-73282 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-73282 | ||
| https://www.openssh.org/releasenotes.html#10.5 | ProductRelease Notes |
Change history (0)
No recorded changes yet.