CVE-2026-60002: Use After Free
Last updated 13 July 2026
Other sources
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.8p1-9 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:10.4p1-1 - Upgrade
Upgrade
OpenSSH (ssh client)to a version that resolves this vulnerability.Fixed in 10.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60002?
The severity of CVE-2026-60002 is rated high with a score of 7.7.
What are the potential impacts of exploiting CVE-2026-60002?
Exploiting CVE-2026-60002 can lead to a use-after-free vulnerability that may allow an attacker to obtain sensitive information or crash the client.
How do I fix CVE-2026-60002?
To fix CVE-2026-60002, upgrade to OpenSSH version 10.4 or later where this vulnerability is addressed.
Which versions of OpenSSH are affected by CVE-2026-60002?
CVE-2026-60002 affects all versions of OpenSSH prior to 10.4.
Is CVE-2026-60002 a client-side vulnerability?
Yes, CVE-2026-60002 is a client-side vulnerability occurring during a key re-exchange when the server changes its host key.