ECHO-03ea-a4eb-03cb

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-03ea-a4eb-03cb.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-03ea-a4eb-03cb
Upstream
Withdrawn
2026-07-16T11:45:02Z
Published
2026-06-23T20:13:57Z
Modified
2026-09-15T03:34:27Z
Summary
Heap out-of-bounds read during cleanup of the GSSAPI "auth-indicators" array (missing trailing NULL). This array is part of Red Hat's downstream GSSAPI authentication-indicators patch and is scoped by upstream to "Red Hat Enterprise Linux versions of OpenSSH". Echo builds from Debian openssh 1:10.4p1-1 (sid), which does not carry that patch: gss-serv.c, auth2-gss.c and gss-genr.c contain zero references to auth indicators, so the vulnerable code path is not present. Debian rates it undetermined/unimportant. https://security-tracker.debian.org/tracker/CVE-2026-55654 https://bugzilla.redhat.com/show_bug.cgi?id=2462493
Details
References

Affected packages

Echo / openssh

Package

Name
openssh
Purl
pkg:deb/echo/openssh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:10.4p1-1+e1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-03ea-a4eb-03cb.json"