Bug#1143924: openssh: CVE-2026-55654

Moritz Mühlenhoff <[email protected]>
Newsgroups gmane.linux.debian.devel.ssh
Message-ID <andLYXV-PMFBBnQO__27778.7033746549$1786203085$gmane$org@pisco.westfalen.local>
Source: openssh
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for openssh.

CVE-2026-55654[0]:
| A flaw was found in OpenSSH. This vulnerability, a heap out-of-
| bounds read, occurs during the cleanup of GSSAPI (Generic Security
| Service Application Programming Interface) indicators when a
| trailing NULL termination is missing in the auth-indicators array. A
| remote attacker, under specific configurations involving GSSAPI
| authentication and a Kerberos environment, could exploit this to
| cause the SSH authentication path to crash or abort. This leads to a
| denial of service (DoS), impacting the availability of the SSH
| service.

This is an issue in the gssapi patch set, for which Red Hat shipped
an update: https://bugzilla.redhat.com/show_bug.cgi?id=2462493

TTBOMK Red Hat is the canonical upstream for the openssh/gssapi
patches and with Debian also shipping support we're probably
also affected?


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-55654
    https://www.cve.org/CVERecord?id=CVE-2026-55654

Please adjust the affected versions in the BTS as needed.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.