VulnerabilityModified
CVE-2023-25136
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.
MEDIUM 6.5EPSS 89.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 89.7%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
- EPSS
- 89.69% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-415
- Affected
- openbsd/openssh · fedoraproject/fedora · netapp/ontap select deploy administration utility · netapp/a250 firmware · netapp/500f firmware · netapp/c250 firmware
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2023/02/13/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/02/22/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/02/22/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/02/23/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/03/06/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/03/09/2Mailing List, Third Party Advisory
- https://bugzilla.mindrot.org/show_bug.cgi?id=3522Exploit, Issue Tracking, Third Party Advisory
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/017_sshd.patch.sigPatch, Vendor Advisory
- https://github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946Patch, Third Party Advisory
- https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/Exploit, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JGAUIXJ3TEKCRKVWFQ6GDAGQFTIIGQQP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7LKQDFZWKYHQ65TBSH2X2HJQ4V2THS3/
- https://news.ycombinator.com/item?id=34711565Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/202307-01Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230309-0003/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2023/02/02/2Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/02/13/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/02/22/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/02/22/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/02/23/3Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/03/06/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/03/09/2Mailing List, Third Party Advisory
- https://bugzilla.mindrot.org/show_bug.cgi?id=3522Exploit, Issue Tracking, Third Party Advisory
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/017_sshd.patch.sigPatch, Vendor Advisory
- https://github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946Patch, Third Party Advisory
- https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/Exploit, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JGAUIXJ3TEKCRKVWFQ6GDAGQFTIIGQQP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7LKQDFZWKYHQ65TBSH2X2HJQ4V2THS3/
- https://news.ycombinator.com/item?id=34711565Issue Tracking, Third Party Advisory
- https://security.gentoo.org/glsa/202307-01Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.