CVE-2025-26466: Pre-authentication Denial of Service attack in OpenSSH - CVE-2025-26466
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.
Other sources
afpfs. The issue was addressed with improved memory handling.
— Apple
afpfs. This issue was addressed with improved checks.
— Apple
Apple Intelligence Reports. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved input sanitization.
— Apple
Audio. A double free issue was addressed with improved memory management.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-26465
- CVE-2025-31246
- CVE-2025-31240
- CVE-2025-31237
- CVE-2025-31251
- CVE-2025-31235
- CVE-2025-31208
- CVE-2025-31196
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-30453
- CVE-2025-24258
- CVE-2025-30448
- CVE-2025-31232
- CVE-2025-24144
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-30440
- CVE-2025-31222
- CVE-2025-24274
- CVE-2025-24142
- CVE-2025-26466
- CVE-2025-31245
- CVE-2025-31224
- CVE-2025-31221
- CVE-2025-31213
- CVE-2025-31247
- CVE-2025-30442
- CVE-2025-31242
- CVE-2025-31220
- CVE-2025-24155
- CVE-2025-31260
- CVE-2025-24222
- CVE-2025-31212
- CVE-2025-31236
- CVE-2025-30443
- CVE-2025-31226
- CVE-2025-24224
- CVE-2025-31218
- CVE-2025-31256
- CVE-2025-31234
- CVE-2025-31244
- CVE-2025-31258
- CVE-2025-31266
- CVE-2025-31249
- CVE-2025-31259
- CVE-2025-31250
- CVE-2025-31248
- CVE-2025-24213
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-31215
- CVE-2025-31204
- CVE-2025-24223
- CVE-2025-31206
- CVE-2025-31217
- CVE-2025-31205
- CVE-2025-31257
- CVE-2025-43374
Frequently Asked Questions
What is the severity of CVE-2025-26466?
CVE-2025-26466 is classified as a Denial of Service vulnerability due to asymmetric resource consumption affecting memory and CPU.
How do I fix CVE-2025-26466?
To mitigate CVE-2025-26466, update to versions 1:9.9p1-3 or later of the OpenSSH package.
Which versions of OpenSSH are affected by CVE-2025-26466?
CVE-2025-26466 affects OpenSSH versions up to and including 1:9.9p1-3.
Can CVE-2025-26466 be exploited remotely?
Yes, CVE-2025-26466 can be exploited remotely, leading to resource exhaustion on the server.
What are the potential impacts of CVE-2025-26466?
The potential impacts of CVE-2025-26466 include service disruption due to excessive consumption of server resources.