Security Alerts

  • Home
  • Security Alerts

OpenSSH Releases Patch for New Pre-Auth Double Free Vulnerability

OpenSSH 9.2 has been released to address security bugs, including a memory safety vulnerability in the OpenSSH server (sshd) tracked as CVE-2023-25136. This vulnerability is a pre-authentication double-free vulnerability that was introduced in version 9.1, but is believed to be not exploitable due to protective measures such as memory allocators and robust privilege separation and sandboxing in the impacted sshd process. Users are advised to update to OpenSSH 9.2 to mitigate potential security threats.

Link

https://thehackernews.com/2023/02/openssh-releases-patch-for-new-pre-auth.html