CVE-2023-25136

Source
https://cve.org/CVERecord?id=CVE-2023-25136
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25136.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-25136
Downstream
Related
Published
2023-02-03T00:00:00Z
Modified
2026-07-15T02:08:05.977241312Z
Summary
[none]
Details

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25136.json"
}
References

Affected packages

Git / github.com/openssh/openssh-portable

Affected ranges

Type
GIT
Repo
https://github.com/openssh/openssh-portable
Events
Database specific
{
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "9.1"
        },
        {
            "last_affected": "9.1"
        }
    ],
    "cpe": "cpe:2.3:a:openbsd:openssh:9.1:*:*:*:*:*:*:*"
}

Affected versions

9.*
9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25136.json"