← volver
CVE-2023-25136CWE-415

CVE-2023-25136

25Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackepss 90%
probabilidad de explotación
90%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."
Productos afectados
n/a · n/a