CVE-2026-73282: Use After Free
Published Aug 11, 2026
·Updated
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
Affected Software
1 affected component
OpenSSH ssh<10.5
Event History
Aug 11, 2026
CVE Published
via MITRE·07:12 PM
Data Sourced
via MITRE·07:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-73282?
The severity of CVE-2026-73282 is classified as medium with a score of 4.8.
2
What are the potential impacts of CVE-2026-73282?
CVE-2026-73282 may lead to memory corruption due to a use-after-free condition, potentially allowing an attacker to compromise the integrity of the application.
3
How do I fix CVE-2026-73282?
To fix CVE-2026-73282, upgrade to OpenSSH version 10.5 or later, where this vulnerability has been addressed.
4
In which software is CVE-2026-73282 found?
CVE-2026-73282 is found in the OpenSSH ssh component prior to version 10.5.
5
What type of vulnerability is CVE-2026-73282?
CVE-2026-73282 is classified as a Use After Free vulnerability.