Armis Logo< Back

CVE-2025-26465:

OpenSSH contains a vulnerability (CVE-2025-26465) that enables a machine-in-the-middle attack when VerifyHostKeyDNS is enabled. The flaw arises from mishandling certain error codes during host-key verification, and an attacker can exploit it after exhausting the client’s memory resources. The issue affects OpenSSH versions up to 9.9p1, with Red Hat advisories guiding patched updates. The CVSSv3.1 base score is 6.8 (Medium), requiring network access and user interaction.


Score
Info
A numerical rating that indicates how dangerous this vulnerability is.

6.8Medium
  • Published Date:Feb 18, 2025
  • CISA KEV Date:*No Data*
  • Industries Affected:20

Threat Predictions

  • EPSS Score:74.0
  • EPSS Percentile:99%

Exploitability

  • Score:1.6
  • Attack Vector:NETWORK
  • Attack Complexity:HIGH
  • Privileges Required:NONE
  • User Interaction:REQUIRED
  • Scope:UNCHANGED

Impact

  • Score:5.2
  • Confidentiality Impact:HIGH
  • Integrity Impact:HIGH
  • Availability Impact:NONE

Description Preview

OpenSSH contains a vulnerability (CVE-2025-26465) that enables a machine-in-the-middle attack when VerifyHostKeyDNS is enabled. The flaw arises from mishandling certain error codes during host-key verification, and an attacker can exploit it after exhausting the client’s memory resources. The issue affects OpenSSH versions up to 9.9p1, with Red Hat advisories guiding patched updates. The CVSSv3.1 base score is 6.8 (Medium), requiring network access and user interaction.

Overview

OpenSSH is vulnerable when VerifyHostKeyDNS is enabled, allowing a remote attacker to conduct a network-based impersonation of a trusted server and carry out a man-in-the-middle attack. The root cause is the mishandling of error codes during host-key verification, which can be exploited after the attacker depletes the client’s memory resources. The vulnerability affects OpenSSH versions up to 9.9p1 (and earlier in the 6.8p1–9.9p1 range) and is addressed by vendor security updates. Red Hat has published advisories RHSA-2025:3837 and RHSA-2025:6993 to provide patches for affected Red Hat systems.

Remediation

  • Apply vendor-supplied patches: Upgrade OpenSSH to a version containing the fix as provided in the Red Hat advisories RHSA-2025:3837 and RHSA-2025:6993. For Red Hat Enterprise Linux 9 and related variants, install the updated openssh package from the vendor updates and advisories.
  • Deploy updates across affected systems: Ensure all deployed OpenSSH versions within the affected scope are updated to the patched release, then restart SSH services (e.g., systemctl restart sshd) and verify the version installed.
  • Validate the patch: Confirm the OpenSSH version is updated to a patched release (as per RHSA advisories) and that VerifyHostKeyDNS usage remains as per your security policy.
  • If a patch cannot be applied promptly: There is no robust, vendor-validated workaround. Monitor vendor communications and consider network-level exposure controls and incident response readiness while patches are being applied.
  • Plan and test: Use a staged rollout to test connectivity and verify that host-key verification via DNS remains secure after patching. Ensure all affected hosts are included in the patching window.

References

Industries Affected

Below is a list of industries most commonly impacted or potentially at risk based on intelligence.

Medium
Utilities icon
Utilities
Retail Trade icon
Retail Trade
Manufacturing icon
Manufacturing
Educational Services icon
Educational Services
Finance and Insurance icon
Finance and Insurance
Public Administration icon
Public Administration
Transportation and Warehousing icon
Transportation and Warehousing
Health Care and Social Assistance icon
Health Care and Social Assistance
Other Services (except Public Administration) icon
Other Services (except Public Administration)
Professional, Scientific, and Technical Services icon
Professional, Scientific, and Technical Services
Low
Mining icon
Mining
Information icon
Information
Construction icon
Construction
Wholesale Trade icon
Wholesale Trade
Real Estate Rental and Leasing icon
Real Estate Rental and Leasing
Accommodation and Food Services icon
Accommodation and Food Services
Arts, Entertainment, and Recreation icon
Arts, Entertainment, and Recreation
Management of Companies and Enterprises icon
Management of Companies and Enterprises
Agriculture, Forestry, Fishing and Hunting icon
Agriculture, Forestry, Fishing and Hunting
Administrative and Support and Waste Management and Remediation Services icon
Administrative and Support and Waste Management and Remediation Services

Focus on What Matters

See everything.Identify true risk.Proactively mitigate threats.Book a Demo

Let's talk!