CVE-2026-106585

Summary

In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data.

Affected Software

VendorProductVersion RangeStatus
OpenBSDOpenSSH0 < 10.6affected

Weaknesses

  • CWE-409: CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)

References