Hi, On Sat, Aug 08, 2026 at 05:29:37PM +0200, Moritz Mühlenhoff wrote: > Source: openssh > X-Debbugs-CC: [email protected] > Severity: important > Tags: security > > Hi, > > The following vulnerability was published for openssh. > > CVE-2026-55654[0]: > | A flaw was found in OpenSSH. This vulnerability, a heap out-of- > | bounds read, occurs during the cleanup of GSSAPI (Generic Security > | Service Application Programming Interface) indicators when a > | trailing NULL termination is missing in the auth-indicators array. A > | remote attacker, under specific configurations involving GSSAPI > | authentication and a Kerberos environment, could exploit this to > | cause the SSH authentication path to crash or abort. This leads to a > | denial of service (DoS), impacting the availability of the SSH > | service. > > This is an issue in the gssapi patch set, for which Red Hat shipped > an update: https://bugzilla.redhat.com/show_bug.cgi?id=2462493 > > TTBOMK Red Hat is the canonical upstream for the openssh/gssapi > patches and with Debian also shipping support we're probably > also affected? > > > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. > > For further information see: > > [0] https://security-tracker.debian.org/tracker/CVE-2026-55654 > https://www.cve.org/CVERecord?id=CVE-2026-55654 > > Please adjust the affected versions in the BTS as needed.
Now that there is openssh-gssapi, should we reassign this bug to src:openssh-gssapi as the GSS_API authentication and key exchange support was droppend in src:openssh/1:10.4p1-5 ? If you agree to do so, we can simply reassign and move the bug reference for the security-tracker to the right source package. Regards, Salvatore

