REDHAT-BUG-1384860: Medium severity OpenSSH OpenSSH vulnerability
A memory exhaustion issue in OpenSSH that can be triggered before user authentication was found. An unauthenticated attacker could consume approx. 400 MB of memory per each connection. The attacker could set up multiple such connections to run out of server’s memory.
Affected versions: openssh-6.8p1, openssh-6.9p1, openssh-7.0p1, openssh-7.1p1, openssh-7.2p1, openssh-7.3p1.
Upstream patch:
http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/kex.c?rev=1.127&content-type=text/x-cvsweb-markup
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1384860?
The severity of REDHAT-BUG-1384860 is high due to its potential for memory exhaustion which can disrupt service.
How can I fix REDHAT-BUG-1384860?
Fix REDHAT-BUG-1384860 by upgrading to OpenSSH version 7.4p1 or later.
What impact does REDHAT-BUG-1384860 have on servers?
REDHAT-BUG-1384860 can lead to significant memory consumption, potentially crashing the server by exhausting available memory.
Who is affected by REDHAT-BUG-1384860?
Users running OpenSSH versions between 6.8p1 and 7.4p1 are affected by REDHAT-BUG-1384860.
Is REDHAT-BUG-1384860 remotely exploitable?
Yes, REDHAT-BUG-1384860 can be exploited remotely by an unauthenticated attacker through multiple connection attempts.