CVE-2023-25136
6.5
MEDIUM
CVSS 3.1
EPSS 88.3%
Description
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."
How to fix CVE-2023-25136
To remediate CVE-2023-25136, upgrade the affected package to a fixed version below.
- —upgrade to 1:9.2p1-1 or later
Is CVE-2023-25136 being exploited?
Likely — EPSS is 88.3%, placing CVE-2023-25136 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 1:9.2p1-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H |