Allocation of Resources Without Limits or Throttling
CVE-2025-26466
Summary
A vulnerability in OpenSSH was discovered when the "VerifyHostKeyDNS" option was enabled. An attacker can execute a machine-in-the-middle attack by impersonating a legitimate server. This issue arises due to OpenSSH mishandling error codes under specific conditions during host key verification. This issue affects openssh-portable versions V_9_5_P1 through V_9_9_P1.
- HIGH
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- NONE
- HIGH
CWE-770 - Allocation of Resources Without Limits or Throttling
The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
References
Advisory Timeline
- Published