Server-side deployments using the sshd-sftp component are affected if they run Apache MINA SSHD 1.0.0 through 2.19.0 or 3.0.0-M1 through 3.0.0-M5. The issue is specific to the SFTP v6 check-file-name and check-file-handle extensions.
An attacker needs SFTP access with low privileges and must invoke the affected SFTP v6 extension against a huge, potentially sparse file while specifying a very small block size, such as 256. This causes the server to generate a large number of hashes and accumulate the reply in memory.
The server can exhaust memory and be taken down. The provided CVSS vector indicates no confidentiality or integrity impact, but high availability impact.
Upgrade to Apache MINA SSHD 2.20.0 or 3.0.0-M6, which impose a maximum reply-size limit. The advisory notes that many SFTP implementations generally limit SFTP message sizes, typically to 256 kB.