REDHAT-BUG-2497936: Use After Free
Published Jul 8, 2026
·Updated
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Affected Software
1 affected component
OpenSSH ssh<10.4
Event History
Jul 8, 2026
Data Sourced
via Red Hat·01:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2497936?
The severity of REDHAT-BUG-2497936 is classified as high with a score of 7.
2
How does REDHAT-BUG-2497936 affect users?
REDHAT-BUG-2497936 can lead to a use-after-free vulnerability on the client side during a key re-exchange.
3
What versions of OpenSSH are impacted by REDHAT-BUG-2497936?
OpenSSH versions prior to 10.4 are impacted by the vulnerability identified in REDHAT-BUG-2497936.
4
How do I fix REDHAT-BUG-2497936?
To fix REDHAT-BUG-2497936, update to OpenSSH version 10.4 or later to mitigate the vulnerability.
5
What type of vulnerability is REDHAT-BUG-2497936 classified as?
REDHAT-BUG-2497936 is classified as a Use After Free vulnerability under the CWE classification.