Asymmetric denial of service In openssh
Description
A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | >=0 <1:9.9p2-1 | 1:9.9p2-1 | |
alpine v3.19 | =5.1_p1-r1 || =5.1_p1-r2 || =5.1p1-r0 || =5.2_p1-r0 || =5.2_p1-r1 || =5.2_p1-r2 || =5.2_p1-r3 || =5.3_p1-r3 || =5.4_p1-r0 || =5.4_p1-r1 || =5.4_p1-r2 || =5.4_p1-r3 || =5.5_p1-r0 || =5.6_p1-r0 || =5.6_p1-r1 || =5.8_p1-r0 || =5.8_p1-r1 || =5.8_p1-r2 || =5.8_p2-r0 || =5.8_p2-r1 || =5.8_p2-r2 || =5.9_p1-r0 || =5.9_p1-r1 || =5.9_p1-r2 || =6.0_p1-r0 || =6.1_p1-r0 || =6.1_p1-r1 || =6.1_p1-r2 || =6.2_p1-r0 || =6.2_p2-r0 || =6.2_p2-r1 || =6.2_p2-r2 || =6.3_p1-r0 || =6.3_p1-r1 || =6.3_p1-r2 || =6.4_p1-r0 || =6.4_p1-r1 || =6.6_p1-r0 || =6.6_p1-r1 || =6.6_p1-r2 || =6.6_p1-r3 || =6.6_p1-r4 || =6.6_p1-r5 || =6.6_p1-r6 || =6.7_p1-r0 || =6.8_p1-r0 || =6.8_p1-r1 || =6.8_p1-r2 || =6.9_p1-r0 || =6.9_p1-r1 || =6.9_p1-r2 || =6.9_p1-r3 || =6.9_p1-r4 || =6.9_p1-r5 || =7.1_p1-r0 || =7.1_p1-r1 || =7.1_p2-r0 || =7.2_p1-r0 || =7.2_p2-r0 || =7.2_p2-r1 || =7.3_p1-r0 || =7.3_p1-r1 || =7.3_p1-r2 || =7.4_p1-r0 || =7.4_p1-r1 || =7.4_p1-r2 || =7.5_p1-r0 || =7.5_p1-r1 || =7.5_p1-r2 || =7.5_p1-r3 || =7.5_p1-r4 || =7.5_p1-r5 || =7.5_p1-r6 || =7.5_p1-r7 || =7.5_p1-r8 || =7.6_p1-r0 || =7.6_p1-r1 || =7.7_p1-r0 || =7.7_p1-r1 || =7.7_p1-r2 || =7.7_p1-r3 || =7.7_p1-r4 || =7.8_p1-r0 || =7.9_p1-r0 || =7.9_p1-r1 || =7.9_p1-r2 || =7.9_p1-r3 || =7.9_p1-r4 || =7.9_p1-r5 || =8.0_p1-r0 || =8.0_p1-r1 || =8.0_p1-r2 || =8.1_p1-r0 || =8.2_p1-r0 || =8.3_p1-r0 || =8.4_p1-r0 || =8.4_p1-r1 || =8.4_p1-r2 || =8.4_p1-r3 || =8.5_p1-r0 || =8.5_p1-r1 || =8.5_p1-r2 || =8.6_p1-r0 || =8.6_p1-r1 || =8.6_p1-r2 || =8.6_p1-r3 || =8.6_p1-r4 || =8.8_p1-r0 || =8.8_p1-r1 || =8.8_p1-r2 || =8.8_p1-r3 || =8.8_p1-r4 || =8.9_p1-r0 || =9.0_p1-r0 || =9.0_p1-r1 || =9.0_p1-r2 || =9.0_p1-r3 || =9.0_p1-r4 || =9.1_p1-r0 || =9.1_p1-r1 || =9.2_p1-r0 || =9.2_p1-r1 || =9.2_p1-r2 || =9.2_p1-r3 || =9.2_p1-r4 || =9.3_p1-r0 || =9.3_p1-r1 || =9.3_p1-r2 || =9.3_p1-r3 || =9.3_p1-r4 || =9.3_p1-r5 || =9.3_p1-r6 || =9.3_p1-r7 || =9.3_p2-r0 || =9.3_p2-r1 || =9.3_p2-r2 || =9.4_p1-r0 || =9.5_p1-r0 || =9.6_p1-r0 || =9.6_p1-r1 || >=0 <9.6_p1-r2 | 9.6_p1-r2 | |
alpine v3.20 | =5.1_p1-r1 || =5.1_p1-r2 || =5.1p1-r0 || =5.2_p1-r0 || =5.2_p1-r1 || =5.2_p1-r2 || =5.2_p1-r3 || =5.3_p1-r3 || =5.4_p1-r0 || =5.4_p1-r1 || =5.4_p1-r2 || =5.4_p1-r3 || =5.5_p1-r0 || =5.6_p1-r0 || =5.6_p1-r1 || =5.8_p1-r0 || =5.8_p1-r1 || =5.8_p1-r2 || =5.8_p2-r0 || =5.8_p2-r1 || =5.8_p2-r2 || =5.9_p1-r0 || =5.9_p1-r1 || =5.9_p1-r2 || =6.0_p1-r0 || =6.1_p1-r0 || =6.1_p1-r1 || =6.1_p1-r2 || =6.2_p1-r0 || =6.2_p2-r0 || =6.2_p2-r1 || =6.2_p2-r2 || =6.3_p1-r0 || =6.3_p1-r1 || =6.3_p1-r2 || =6.4_p1-r0 || =6.4_p1-r1 || =6.6_p1-r0 || =6.6_p1-r1 || =6.6_p1-r2 || =6.6_p1-r3 || =6.6_p1-r4 || =6.6_p1-r5 || =6.6_p1-r6 || =6.7_p1-r0 || =6.8_p1-r0 || =6.8_p1-r1 || =6.8_p1-r2 || =6.9_p1-r0 || =6.9_p1-r1 || =6.9_p1-r2 || =6.9_p1-r3 || =6.9_p1-r4 || =6.9_p1-r5 || =7.1_p1-r0 || =7.1_p1-r1 || =7.1_p2-r0 || =7.2_p1-r0 || =7.2_p2-r0 || =7.2_p2-r1 || =7.3_p1-r0 || =7.3_p1-r1 || =7.3_p1-r2 || =7.4_p1-r0 || =7.4_p1-r1 || =7.4_p1-r2 || =7.5_p1-r0 || =7.5_p1-r1 || =7.5_p1-r2 || =7.5_p1-r3 || =7.5_p1-r4 || =7.5_p1-r5 || =7.5_p1-r6 || =7.5_p1-r7 || =7.5_p1-r8 || =7.6_p1-r0 || =7.6_p1-r1 || =7.7_p1-r0 || =7.7_p1-r1 || =7.7_p1-r2 || =7.7_p1-r3 || =7.7_p1-r4 || =7.8_p1-r0 || =7.9_p1-r0 || =7.9_p1-r1 || =7.9_p1-r2 || =7.9_p1-r3 || =7.9_p1-r4 || =7.9_p1-r5 || =8.0_p1-r0 || =8.0_p1-r1 || =8.0_p1-r2 || =8.1_p1-r0 || =8.2_p1-r0 || =8.3_p1-r0 || =8.4_p1-r0 || =8.4_p1-r1 || =8.4_p1-r2 || =8.4_p1-r3 || =8.5_p1-r0 || =8.5_p1-r1 || =8.5_p1-r2 || =8.6_p1-r0 || =8.6_p1-r1 || =8.6_p1-r2 || =8.6_p1-r3 || =8.6_p1-r4 || =8.8_p1-r0 || =8.8_p1-r1 || =8.8_p1-r2 || =8.8_p1-r3 || =8.8_p1-r4 || =8.9_p1-r0 || =9.0_p1-r0 || =9.0_p1-r1 || =9.0_p1-r2 || =9.0_p1-r3 || =9.0_p1-r4 || =9.1_p1-r0 || =9.1_p1-r1 || =9.2_p1-r0 || =9.2_p1-r1 || =9.2_p1-r2 || =9.2_p1-r3 || =9.2_p1-r4 || =9.3_p1-r0 || =9.3_p1-r1 || =9.3_p1-r2 || =9.3_p1-r3 || =9.3_p1-r4 || =9.3_p1-r5 || =9.3_p1-r6 || =9.3_p1-r7 || =9.3_p2-r0 || =9.3_p2-r1 || =9.3_p2-r2 || =9.4_p1-r0 || =9.5_p1-r0 || =9.6_p1-r0 || =9.7_p1-r0 || =9.7_p1-r1 || =9.7_p1-r2 || =9.7_p1-r3 || =9.7_p1-r4 || >=0 <9.7_p1-r5 | 9.7_p1-r5 | |
alpine v3.21 | =5.1_p1-r1 || =5.1_p1-r2 || =5.1p1-r0 || =5.2_p1-r0 || =5.2_p1-r1 || =5.2_p1-r2 || =5.2_p1-r3 || =5.3_p1-r3 || =5.4_p1-r0 || =5.4_p1-r1 || =5.4_p1-r2 || =5.4_p1-r3 || =5.5_p1-r0 || =5.6_p1-r0 || =5.6_p1-r1 || =5.8_p1-r0 || =5.8_p1-r1 || =5.8_p1-r2 || =5.8_p2-r0 || =5.8_p2-r1 || =5.8_p2-r2 || =5.9_p1-r0 || =5.9_p1-r1 || =5.9_p1-r2 || =6.0_p1-r0 || =6.1_p1-r0 || =6.1_p1-r1 || =6.1_p1-r2 || =6.2_p1-r0 || =6.2_p2-r0 || =6.2_p2-r1 || =6.2_p2-r2 || =6.3_p1-r0 || =6.3_p1-r1 || =6.3_p1-r2 || =6.4_p1-r0 || =6.4_p1-r1 || =6.6_p1-r0 || =6.6_p1-r1 || =6.6_p1-r2 || =6.6_p1-r3 || =6.6_p1-r4 || =6.6_p1-r5 || =6.6_p1-r6 || =6.7_p1-r0 || =6.8_p1-r0 || =6.8_p1-r1 || =6.8_p1-r2 || =6.9_p1-r0 || =6.9_p1-r1 || =6.9_p1-r2 || =6.9_p1-r3 || =6.9_p1-r4 || =6.9_p1-r5 || =7.1_p1-r0 || =7.1_p1-r1 || =7.1_p2-r0 || =7.2_p1-r0 || =7.2_p2-r0 || =7.2_p2-r1 || =7.3_p1-r0 || =7.3_p1-r1 || =7.3_p1-r2 || =7.4_p1-r0 || =7.4_p1-r1 || =7.4_p1-r2 || =7.5_p1-r0 || =7.5_p1-r1 || =7.5_p1-r2 || =7.5_p1-r3 || =7.5_p1-r4 || =7.5_p1-r5 || =7.5_p1-r6 || =7.5_p1-r7 || =7.5_p1-r8 || =7.6_p1-r0 || =7.6_p1-r1 || =7.7_p1-r0 || =7.7_p1-r1 || =7.7_p1-r2 || =7.7_p1-r3 || =7.7_p1-r4 || =7.8_p1-r0 || =7.9_p1-r0 || =7.9_p1-r1 || =7.9_p1-r2 || =7.9_p1-r3 || =7.9_p1-r4 || =7.9_p1-r5 || =8.0_p1-r0 || =8.0_p1-r1 || =8.0_p1-r2 || =8.1_p1-r0 || =8.2_p1-r0 || =8.3_p1-r0 || =8.4_p1-r0 || =8.4_p1-r1 || =8.4_p1-r2 || =8.4_p1-r3 || =8.5_p1-r0 || =8.5_p1-r1 || =8.5_p1-r2 || =8.6_p1-r0 || =8.6_p1-r1 || =8.6_p1-r2 || =8.6_p1-r3 || =8.6_p1-r4 || =8.8_p1-r0 || =8.8_p1-r1 || =8.8_p1-r2 || =8.8_p1-r3 || =8.8_p1-r4 || =8.9_p1-r0 || =9.0_p1-r0 || =9.0_p1-r1 || =9.0_p1-r2 || =9.0_p1-r3 || =9.0_p1-r4 || =9.1_p1-r0 || =9.1_p1-r1 || =9.2_p1-r0 || =9.2_p1-r1 || =9.2_p1-r2 || =9.2_p1-r3 || =9.2_p1-r4 || =9.3_p1-r0 || =9.3_p1-r1 || =9.3_p1-r2 || =9.3_p1-r3 || =9.3_p1-r4 || =9.3_p1-r5 || =9.3_p1-r6 || =9.3_p1-r7 || =9.3_p2-r0 || =9.3_p2-r1 || =9.3_p2-r2 || =9.4_p1-r0 || =9.5_p1-r0 || =9.6_p1-r0 || =9.7_p1-r0 || =9.7_p1-r1 || =9.7_p1-r2 || =9.7_p1-r3 || =9.8_p1-r0 || =9.8_p1-r1 || =9.9_p1-r0 || =9.9_p1-r1 || =9.9_p1-r2 || >=0 <9.9_p2-r0 | 9.9_p2-r0 | |
alpine v3.22 | =5.1_p1-r1 || =5.1_p1-r2 || =5.1p1-r0 || =5.2_p1-r0 || =5.2_p1-r1 || =5.2_p1-r2 || =5.2_p1-r3 || =5.3_p1-r3 || =5.4_p1-r0 || =5.4_p1-r1 || =5.4_p1-r2 || =5.4_p1-r3 || =5.5_p1-r0 || =5.6_p1-r0 || =5.6_p1-r1 || =5.8_p1-r0 || =5.8_p1-r1 || =5.8_p1-r2 || =5.8_p2-r0 || =5.8_p2-r1 || =5.8_p2-r2 || =5.9_p1-r0 || =5.9_p1-r1 || =5.9_p1-r2 || =6.0_p1-r0 || =6.1_p1-r0 || =6.1_p1-r1 || =6.1_p1-r2 || =6.2_p1-r0 || =6.2_p2-r0 || =6.2_p2-r1 || =6.2_p2-r2 || =6.3_p1-r0 || =6.3_p1-r1 || =6.3_p1-r2 || =6.4_p1-r0 || =6.4_p1-r1 || =6.6_p1-r0 || =6.6_p1-r1 || =6.6_p1-r2 || =6.6_p1-r3 || =6.6_p1-r4 || =6.6_p1-r5 || =6.6_p1-r6 || =6.7_p1-r0 || =6.8_p1-r0 || =6.8_p1-r1 || =6.8_p1-r2 || =6.9_p1-r0 || =6.9_p1-r1 || =6.9_p1-r2 || =6.9_p1-r3 || =6.9_p1-r4 || =6.9_p1-r5 || =7.1_p1-r0 || =7.1_p1-r1 || =7.1_p2-r0 || =7.2_p1-r0 || =7.2_p2-r0 || =7.2_p2-r1 || =7.3_p1-r0 || =7.3_p1-r1 || =7.3_p1-r2 || =7.4_p1-r0 || =7.4_p1-r1 || =7.4_p1-r2 || =7.5_p1-r0 || =7.5_p1-r1 || =7.5_p1-r2 || =7.5_p1-r3 || =7.5_p1-r4 || =7.5_p1-r5 || =7.5_p1-r6 || =7.5_p1-r7 || =7.5_p1-r8 || =7.6_p1-r0 || =7.6_p1-r1 || =7.7_p1-r0 || =7.7_p1-r1 || =7.7_p1-r2 || =7.7_p1-r3 || =7.7_p1-r4 || =7.8_p1-r0 || =7.9_p1-r0 || =7.9_p1-r1 || =7.9_p1-r2 || =7.9_p1-r3 || =7.9_p1-r4 || =7.9_p1-r5 || =8.0_p1-r0 || =8.0_p1-r1 || =8.0_p1-r2 || =8.1_p1-r0 || =8.2_p1-r0 || =8.3_p1-r0 || =8.4_p1-r0 || =8.4_p1-r1 || =8.4_p1-r2 || =8.4_p1-r3 || =8.5_p1-r0 || =8.5_p1-r1 || =8.5_p1-r2 || =8.6_p1-r0 || =8.6_p1-r1 || =8.6_p1-r2 || =8.6_p1-r3 || =8.6_p1-r4 || =8.8_p1-r0 || =8.8_p1-r1 || =8.8_p1-r2 || =8.8_p1-r3 || =8.8_p1-r4 || =8.9_p1-r0 || =9.0_p1-r0 || =9.0_p1-r1 || =9.0_p1-r2 || =9.0_p1-r3 || =9.0_p1-r4 || =9.1_p1-r0 || =9.1_p1-r1 || =9.2_p1-r0 || =9.2_p1-r1 || =9.2_p1-r2 || =9.2_p1-r3 || =9.2_p1-r4 || =9.3_p1-r0 || =9.3_p1-r1 || =9.3_p1-r2 || =9.3_p1-r3 || =9.3_p1-r4 || =9.3_p1-r5 || =9.3_p1-r6 || =9.3_p1-r7 || =9.3_p2-r0 || =9.3_p2-r1 || =9.3_p2-r2 || =9.4_p1-r0 || =9.5_p1-r0 || =9.6_p1-r0 || =9.7_p1-r0 || =9.7_p1-r1 || =9.7_p1-r2 || =9.7_p1-r3 || =9.8_p1-r0 || =9.8_p1-r1 || =9.9_p1-r0 || =9.9_p1-r1 || =9.9_p1-r2 || >=0 <9.9_p2-r0 | 9.9_p2-r0 | |
debian 14 | >=0 <1:9.9p2-1 | 1:9.9p2-1 | |
alpine v3.23 | =5.1_p1-r1 || =5.1_p1-r2 || =5.1p1-r0 || =5.2_p1-r0 || =5.2_p1-r1 || =5.2_p1-r2 || =5.2_p1-r3 || =5.3_p1-r3 || =5.4_p1-r0 || =5.4_p1-r1 || =5.4_p1-r2 || =5.4_p1-r3 || =5.5_p1-r0 || =5.6_p1-r0 || =5.6_p1-r1 || =5.8_p1-r0 || =5.8_p1-r1 || =5.8_p1-r2 || =5.8_p2-r0 || =5.8_p2-r1 || =5.8_p2-r2 || =5.9_p1-r0 || =5.9_p1-r1 || =5.9_p1-r2 || =6.0_p1-r0 || =6.1_p1-r0 || =6.1_p1-r1 || =6.1_p1-r2 || =6.2_p1-r0 || =6.2_p2-r0 || =6.2_p2-r1 || =6.2_p2-r2 || =6.3_p1-r0 || =6.3_p1-r1 || =6.3_p1-r2 || =6.4_p1-r0 || =6.4_p1-r1 || =6.6_p1-r0 || =6.6_p1-r1 || =6.6_p1-r2 || =6.6_p1-r3 || =6.6_p1-r4 || =6.6_p1-r5 || =6.6_p1-r6 || =6.7_p1-r0 || =6.8_p1-r0 || =6.8_p1-r1 || =6.8_p1-r2 || =6.9_p1-r0 || =6.9_p1-r1 || =6.9_p1-r2 || =6.9_p1-r3 || =6.9_p1-r4 || =6.9_p1-r5 || =7.1_p1-r0 || =7.1_p1-r1 || =7.1_p2-r0 || =7.2_p1-r0 || =7.2_p2-r0 || =7.2_p2-r1 || =7.3_p1-r0 || =7.3_p1-r1 || =7.3_p1-r2 || =7.4_p1-r0 || =7.4_p1-r1 || =7.4_p1-r2 || =7.5_p1-r0 || =7.5_p1-r1 || =7.5_p1-r2 || =7.5_p1-r3 || =7.5_p1-r4 || =7.5_p1-r5 || =7.5_p1-r6 || =7.5_p1-r7 || =7.5_p1-r8 || =7.6_p1-r0 || =7.6_p1-r1 || =7.7_p1-r0 || =7.7_p1-r1 || =7.7_p1-r2 || =7.7_p1-r3 || =7.7_p1-r4 || =7.8_p1-r0 || =7.9_p1-r0 || =7.9_p1-r1 || =7.9_p1-r2 || =7.9_p1-r3 || =7.9_p1-r4 || =7.9_p1-r5 || =8.0_p1-r0 || =8.0_p1-r1 || =8.0_p1-r2 || =8.1_p1-r0 || =8.2_p1-r0 || =8.3_p1-r0 || =8.4_p1-r0 || =8.4_p1-r1 || =8.4_p1-r2 || =8.4_p1-r3 || =8.5_p1-r0 || =8.5_p1-r1 || =8.5_p1-r2 || =8.6_p1-r0 || =8.6_p1-r1 || =8.6_p1-r2 || =8.6_p1-r3 || =8.6_p1-r4 || =8.8_p1-r0 || =8.8_p1-r1 || =8.8_p1-r2 || =8.8_p1-r3 || =8.8_p1-r4 || =8.9_p1-r0 || =9.0_p1-r0 || =9.0_p1-r1 || =9.0_p1-r2 || =9.0_p1-r3 || =9.0_p1-r4 || =9.1_p1-r0 || =9.1_p1-r1 || =9.2_p1-r0 || =9.2_p1-r1 || =9.2_p1-r2 || =9.2_p1-r3 || =9.2_p1-r4 || =9.3_p1-r0 || =9.3_p1-r1 || =9.3_p1-r2 || =9.3_p1-r3 || =9.3_p1-r4 || =9.3_p1-r5 || =9.3_p1-r6 || =9.3_p1-r7 || =9.3_p2-r0 || =9.3_p2-r1 || =9.3_p2-r2 || =9.4_p1-r0 || =9.5_p1-r0 || =9.6_p1-r0 || =9.7_p1-r0 || =9.7_p1-r1 || =9.7_p1-r2 || =9.7_p1-r3 || =9.8_p1-r0 || =9.8_p1-r1 || =9.9_p1-r0 || =9.9_p1-r1 || =9.9_p1-r2 || >=0 <9.9_p2-r0 | 9.9_p2-r0 |
Aliases
References
Does your application use this vulnerable software?
During the free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.