QID 38888

Date Published: 2023-02-03

QID 38888: OpenSSH server 9.1 'sshd(8)' Double-Free Vulnerability

Open SSH 9.1 have a pre-authentication double-free memory fault. It occurs in the unprivileged pre-auth process that is subject to chroot(2).

Affected Versions:
OpenSSH Version 9.1

QID Detection Logic (Unauthenticated):
This QID detects the vulnerable Openssh based on SSH banner.

This vulnerability can be triggered in the default configuration of the OpenSSH server (sshd).

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    This has been fixed in OpenSSH 9.2 and can be referred under OpenSSH 9.2
    Vendor References

    CVEs related to QID 38888

    Software Advisories
    Advisory ID Software Component Link
    OpenSSH 9.2/9.2p1 URL Logo www.openssh.com/releasenotes.html#9.2