Skip to main content

Detection of Error Condition Without Action

CVE-2025-26465

Severity Medium
Score 6.8/10

Summary

A vulnerability was found in OpenSSH when the "VerifyHostKeyDNS" option was enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legitimate server. This issue occurs because OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high. This issue affects versions V_6_8_P1 through V_9_8_P1.

  • HIGH
  • NETWORK
  • HIGH
  • UNCHANGED
  • REQUIRED
  • NONE
  • HIGH
  • NONE

CWE-390 - Detection of Error Condition Without Action

The software detects a specific error, but takes no actions to handle the error.

Advisory Timeline

  • Published