CVE-2026-73282: Use After Free
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:10.5p1-1 - Upgrade
Upgrade
debian/openssh-gssapito a version that resolves this vulnerability.Fixed in 1:10.5p1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73282?
The severity of CVE-2026-73282 is classified as medium with a score of 4.8.
What are the potential impacts of CVE-2026-73282?
CVE-2026-73282 may lead to memory corruption due to a use-after-free condition, potentially allowing an attacker to compromise the integrity of the application.
How do I fix CVE-2026-73282?
To fix CVE-2026-73282, upgrade to OpenSSH version 10.5 or later, where this vulnerability has been addressed.
In which software is CVE-2026-73282 found?
CVE-2026-73282 is found in the OpenSSH ssh component prior to version 10.5.
What type of vulnerability is CVE-2026-73282?
CVE-2026-73282 is classified as a Use After Free vulnerability.