CVE Vulnerabilities

CVE-2016-8858

Published: Dec 09, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
5.8 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that OpenSSH upstream does not consider this as a security issue.

Affected Software

NameVendorStart VersionEnd Version
OpensshOpenbsd6.8 (including)6.8 (including)
OpensshOpenbsd6.9 (including)6.9 (including)
OpensshOpenbsd7.0 (including)7.0 (including)
OpensshOpenbsd7.1 (including)7.1 (including)
OpensshOpenbsd7.2 (including)7.2 (including)
OpensshOpenbsd7.3 (including)7.3 (including)
OpensshUbuntuesm-infra-legacy/trusty*
OpensshUbuntuesm-infra/xenial*
OpensshUbuntuprecise*
OpensshUbuntuprecise/esm*
OpensshUbuntutrusty*
OpensshUbuntutrusty/esm*
OpensshUbuntuvivid/stable-phone-overlay*
OpensshUbuntuvivid/ubuntu-core*
OpensshUbuntuxenial*
OpensshUbuntuyakkety*

References