CVE-2025-26465
Description
Moderate: openssh security update
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2025-6993.html
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2025-16823.html
Vendor advisory: alma — https://bugzilla.redhat.com/2344780
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2025:16823
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-26465
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:6993
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-26465.html
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:16823
Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-openssh
Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://www.openssh.com/releasenotes.html#9.9p2
Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2025:6993
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| rocky | 8 | fixed | |
| sles | affected | | |
| rocky | 9 | fixed | |
| debian | 11.0 | affected | |
| debian | 12.0 | affected | |
| rhel | 9.0 | affected | |
| debian | bookworm | fixed | 1:9.2p1-2+deb12u5 |
| debian | bullseye | fixed | 1:8.4p1-5+deb11u4 |
| debian | forky | fixed | 1:9.9p2-1 |
| debian | sid | fixed | 1:9.9p2-1 |
| debian | trixie | fixed | 1:9.9p2-1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| openbsd | openssh | {"startIncluding":"6.9","endIncluding":"9.8"} | |
| openbsd | openssh | 6.8 | |
| openbsd | openssh | 9.9 | |
| netapp | active_iq_unified_manager | - | |
| netapp | ontap | 9 | |
| redhat | openshift_container_platform | 4.0 | |
References
- https://access.redhat.com/errata/RHSA-2025:6993
- https://access.redhat.com/errata/RHSA-2025:16823
- https://access.redhat.com/errata/RHSA-2025:3837
- https://access.redhat.com/errata/RHSA-2025:8385
- https://access.redhat.com/security/cve/CVE-2025-26465
- https://access.redhat.com/solutions/7109879
- https://bugzilla.redhat.com/show_bug.cgi?id=2344780
- https://seclists.org/oss-sec/2025/q1/144
- http://seclists.org/fulldisclosure/2025/Feb/18
- http://seclists.org/fulldisclosure/2025/May/7
- http://seclists.org/fulldisclosure/2025/May/8
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-discovers-two-vulnerabilities-in-openssh-cve-2025-26465-cve-2025-26466
- https://bugzilla.suse.com/show_bug.cgi?id=1237040
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig
- https://lists.debian.org/debian-lts-announce/2025/02/msg00020.html
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.html
- https://security-tracker.debian.org/tracker/CVE-2025-26465
- https://security.netapp.com/advisory/ntap-20250228-0003/
- https://ubuntu.com/security/CVE-2025-26465
- https://www.openssh.com/releasenotes.html#9.9p2
- https://www.openwall.com/lists/oss-security/2025/02/18/1
- https://www.openwall.com/lists/oss-security/2025/02/18/4
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-detect-vulnerable-openssh
- https://www.vicarius.io/vsociety/posts/cve-2025-26465-mitigate-vulnerable-openssh
CWEs
CWE-390
Verify integrity in audit chain (admin only). AS-IS.