CVE-2026-55654

EUVD-2026-38414
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 32.43%
Affected Products (NVD)
VendorProductVersion
openbsdopenssh
-
redhathardened_images
-
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssh
bookworm
undetermined
bookworm (security)
undetermined
bullseye
undetermined
bullseye (security)
undetermined
forky
undetermined
sid
undetermined
trixie
undetermined
trixie (security)
undetermined
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssh
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
questing
ignored
resolute
deferred
trusty
deferred
xenial
deferred
openssh-ssh1
bionic
ignored
focal
ignored
jammy
ignored
noble
ignored
questing
ignored
resolute
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
openssh
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-askpass
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-clients
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-keycat
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-server
RHEL 9
0:9.9p1-9.el9_8
fixed
pam
RHEL 9
0:0.10.4-7.9.el9_8
fixed