DNA View

CVE-2025-26466

Medium
Low Medium High Critical
5.9
CVSS Score
Published: Feb 28, 2025
Last Modified: Feb 10, 2026

Vulnerability Description

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
N
Attack Complexity
H
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
N
Integrity
N
Availability
H

Known Affected Software

10 configuration(s) from 3 vendor(s)

ubuntu_linux
Version:
24.04
CPE:
cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:*
ubuntu_linux
Version:
24.10
CPE:
cpe:2.3:o:canonical:ubuntu_linux:24.10:*:*:*:*:*:*:*
debian_linux
Version:
12.0
CPE:
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
debian_linux
Version:
13.0
CPE:
cpe:2.3:o:debian:debian_linux:13.0:*:*:*:*:*:*:*
debian_linux
Version:
11.0
CPE:
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
openssh
Version:
9.6
CPE:
cpe:2.3:a:openbsd:openssh:9.6:-:*:*:*:*:*:*
openssh
Version:
9.7
CPE:
cpe:2.3:a:openbsd:openssh:9.7:-:*:*:*:*:*:*
openssh
Version:
9.8
CPE:
cpe:2.3:a:openbsd:openssh:9.8:-:*:*:*:*:*:*
openssh
Version:
9.9
CPE:
cpe:2.3:a:openbsd:openssh:9.9:-:*:*:*:*:*:*
openssh
Version:
9.5
CPE:
cpe:2.3:a:openbsd:openssh:9.5:-:*:*:*:*:*:*
This vulnerability affects 10 software configuration(s). Ensure you patch all affected systems.

Available Security Patches

4 patches available from vendors

View All Patches
Microsoft

2025-Feb-CVE-2025-26466

CVE-2025-26466: Openssh: denial-of-service in openssh

Severity
Unknown
Released
Oct 24, 2025
Security Update
Microsoft

2025-Mar-CVE-2025-26466

CVE-2025-26466: None

Severity
Unknown
Released
Sep 04, 2025
Security Update
Oracle

CPUAPR2025

Oracle Critical Patch Update Advisory - April 2025

Severity
Critical
Released
Apr 15, 2025
Restart Required
Security Update
SUSE

CVE-2025-26466

CVE-2025-26466

Severity
Unknown
Released
Feb 20, 2025
Security Update

References & Resources

Severity Details

5.9
out of 10.0
Medium

Weakness Type (CWE)

CWE-770

Allocation of Resources Without Limits or Throttling

Description
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Exploit Likelihood
High
Typical Severity
Medium
Abstraction Level
Base

Key Information

Published Date
February 28, 2025