Hi,

On Sat, Aug 08, 2026 at 05:29:37PM +0200, Moritz Mühlenhoff wrote:
> Source: openssh
> X-Debbugs-CC: [email protected]
> Severity: important
> Tags: security
> 
> Hi,
> 
> The following vulnerability was published for openssh.
> 
> CVE-2026-55654[0]:
> | A flaw was found in OpenSSH. This vulnerability, a heap out-of-
> | bounds read, occurs during the cleanup of GSSAPI (Generic Security
> | Service Application Programming Interface) indicators when a
> | trailing NULL termination is missing in the auth-indicators array. A
> | remote attacker, under specific configurations involving GSSAPI
> | authentication and a Kerberos environment, could exploit this to
> | cause the SSH authentication path to crash or abort. This leads to a
> | denial of service (DoS), impacting the availability of the SSH
> | service.
> 
> This is an issue in the gssapi patch set, for which Red Hat shipped
> an update: https://bugzilla.redhat.com/show_bug.cgi?id=2462493
> 
> TTBOMK Red Hat is the canonical upstream for the openssh/gssapi
> patches and with Debian also shipping support we're probably
> also affected?
> 
> 
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
> 
> For further information see:
> 
> [0] https://security-tracker.debian.org/tracker/CVE-2026-55654
>     https://www.cve.org/CVERecord?id=CVE-2026-55654
> 
> Please adjust the affected versions in the BTS as needed.

Now that there is openssh-gssapi, should we reassign this bug to
src:openssh-gssapi as the GSS_API authentication and key exchange
support was droppend in src:openssh/1:10.4p1-5 ?

If you agree to do so, we can simply reassign and move the bug
reference for the security-tracker to the right source package.

Regards,
Salvatore

Reply via email to