← All CVEs

CVE-2023-25136

medium · 6.5

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."

6.5
CVSS
89.7%
EPSS (exploit prob.)
100th
EPSS percentile
2023-02-03
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Weaknesses

CWE-415

Affected products

VendorProductAffected versions
openbsdopenssh9.1
fedoraprojectfedora37
fedoraprojectfedora38
netappontap_select_deploy_administration_utilityall versions
netappa250_firmwareall versions
netappa250all versions
netapp500f_firmwareall versions
netapp500fall versions
netappc250_firmwareall versions
netappc250all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-25136