Back

MEDIUM

openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client

Published Aug 11, 2026

Description

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

Affected products

Remediation

Red Hat statement

A use-after-free flaw exists in OpenSSH's ssh client during concurrent remote-forwarding processing. When adding a remote forward via the local session multiplexing socket while a server remote-forward open request is pending, realloc data management fails, freeing memory that remains actively referenced. A remote attacker with high attack complexity can exploit this timing window to corrupt process memory, posing a low impact to confidentiality, integrity, and availability.

Red Hat mitigation

Avoid issuing dynamic remote-forwarding commands over active SSH multiplexing connections, or disable socket multiplexing by setting ControlMaster no in ~/.ssh/config.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 11, 2026
Updated Aug 11, 2026
Reserved Aug 11, 2026
CISA Vulnrichment
Updated Aug 11, 2026
NVD
Status Analyzed
Modified Sep 4, 2026
Red Hat
Severity Moderate
Public date Aug 11, 2026
ENISA EUVD
Assigner mitre
Published Aug 11, 2026
Updated Aug 11, 2026
Exploited since n/a
EUVD-2026-56891