CVE-2026-55654

EUVD-2026-38414
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 36.24%
Affected Products (NVD)
VendorProductVersion
openbsdopenssh
-
redhathardened_images
-
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssh
bookworm
postponed
bookworm (security)
vulnerable
forky
1:10.5p1-1
fixed
sid
1:10.5p1-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
openssh-gssapi
forky
vulnerable
sid
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssh
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
questing
ignored
resolute
not-affected
trusty
not-affected
xenial
not-affected
openssh-ssh1
bionic
ignored
focal
ignored
jammy
ignored
noble
ignored
questing
ignored
resolute
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
openssh
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-askpass
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-clients
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-keycat
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-server
RHEL 9
0:9.9p1-9.el9_8
fixed
pam
RHEL 9
0:0.10.4-7.9.el9_8
fixed