https://seclists.org/oss-sec/2025/q1/214: Triton Product Security announcement: Debian 12 LX image from 2024-07 has static SSH keys
Published Mar 13, 2025
·Updated
Affected Software
3 affected components
Joyent SmartOS
Joyent Triton Data Center
Debian Debian 12 LX zone image
Frequently Asked Questions
1
What is the severity of TPS-2025-002?
TPS-2025-002 has been rated as a critical vulnerability due to the presence of static SSH keys in Debian 12 LX images.
2
How do I fix TPS-2025-002?
To fix TPS-2025-002, replace the static SSH keys in the affected Debian 12 LX images with unique, secure keys.
3
Which systems are affected by TPS-2025-002?
TPS-2025-002 affects both standalone SmartOS and the Triton Data Center environments.
4
What version of Debian is impacted by TPS-2025-002?
Debian 12 LX zone image version 60f76fd2-143f-4f57-819b-1ae32684e81b from July 2024 is impacted by TPS-2025-002.
5
Is there a public advisory for TPS-2025-002?
Yes, a public advisory for TPS-2025-002 can be found on the security.tritondatacenter.com website.