CVE-2026-106584
2.5
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Summary
In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenBSD | OpenSSH | 0 < 10.6 | affected |
Weaknesses
- CWE-193: CWE-193 Off-by-one Error
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.