FG-IR-25-122: Pre-authentication Denial of Service attack in OpenSSH - CVE-2025-26466
CVE-2025-26466A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-25-122?
The severity of FG-IR-25-122 is classified as critical due to the potential for exploitation by a malicious client.
How do I fix FG-IR-25-122?
To fix FG-IR-25-122, update your affected Fortinet products to the recommended versions as specified in the remediation details.
What products are affected by FG-IR-25-122?
FG-IR-25-122 affects various Fortinet products including FortiADC, FortiAnalyzer, FortiManager, and FortiDDoS-F.
What are the minimum versions that address FG-IR-25-122?
The minimum versions that address FG-IR-25-122 include FortiADC 7.6.2, FortiAnalyzer 7.6.3, and FortiManager 7.6.3.
Is FG-IR-25-122 reversible once exploited?
Once exploited, the effects of FG-IR-25-122 can lead to resource depletion, which may not be easily reversible without proper security measures.