QID 38888
Date Published: 2023-02-03
QID 38888: OpenSSH server 9.1 'sshd(8)' Double-Free Vulnerability
Open SSH 9.1 have a pre-authentication double-free memory fault. It occurs in the unprivileged pre-auth process that is subject to chroot(2).
Affected Versions:
OpenSSH Version 9.1
QID Detection Logic (Unauthenticated):
This QID detects the vulnerable Openssh based on SSH banner.
This vulnerability can be triggered in the default configuration of the OpenSSH server (sshd).
Solution
This has been fixed in OpenSSH 9.2 and can be referred under OpenSSH 9.2
Vendor References
- OpenSSH 9.1 Double free -
www.openssh.com/releasenotes.html#9.2
CVEs related to QID 38888
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OpenSSH 9.2/9.2p1 |
|