CVE-2025-26465

medium
Published 2025-05-13 · Modified 2025-06-05
CVSS v3
6.8
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS v2
VIR risk
6.8

Description

Moderate: openssh security update

Predictions

Exploit likelihood
77%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2025-6993.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2025-16823.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2344780

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2025:16823

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-26465

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:6993

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-26465.html

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:16823

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-openssh

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://www.openssh.com/releasenotes.html#9.9p2

vendor Authored 2026-05-27

Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2025:6993

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
suse slesaffected
rockylinux rocky9fixed
debian debian11.0affected
debian debian12.0affected
redhat rhel9.0affected
debian debianbookwormfixed1:9.2p1-2+deb12u5
debian debianbullseyefixed1:8.4p1-5+deb11u4
debian debianforkyfixed1:9.9p2-1
debian debiansidfixed1:9.9p2-1
debian debiantrixiefixed1:9.9p2-1

Application impact

VendorProductVersionsFixed
openbsdopenssh{"startIncluding":"6.9","endIncluding":"9.8"}
openbsdopenssh6.8
openbsdopenssh9.9
netappactive_iq_unified_manager-
netappontap9
redhatopenshift_container_platform4.0

References

CWEs

CWE-390

Verify integrity in audit chain (admin only). AS-IS.