CVE-2026-55654

Summary

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Enterprise Linux 100:9.9p1-25.el10_2 < *unaffected
Red HatRed Hat Enterprise Linux 90:9.9p1-9.el9_8 < *unaffected
Red HatRed Hat Enterprise Linux 90:9.9p1-9.el9_8 < *unaffected
Red HatRed Hat Hardened Images10.3p1-6.hum1 < *unaffected
Red HatRed Hat Update Infrastructure 51786435483 < *unaffected
Red HatRed Hat Update Infrastructure 51786533529 < *unaffected
Red HatRed Hat Update Infrastructure 51787135742 < *unaffected
Red HatRed Hat Update Infrastructure 51787241260 < *unaffected

Weaknesses

  • CWE-125: Out-of-bounds Read

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References