Detection of Error Condition Without Action
CVE-2025-26465
Summary
A vulnerability was found in OpenSSH when the "VerifyHostKeyDNS" option was enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legitimate server. This issue occurs because OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high. This issue affects versions V_6_8_P1 through V_9_8_P1.
- HIGH
- NETWORK
- HIGH
- UNCHANGED
- REQUIRED
- NONE
- HIGH
- NONE
CWE-390 - Detection of Error Condition Without Action
The software detects a specific error, but takes no actions to handle the error.
References
Advisory Timeline
- Published