CVE Vulnerabilities

CVE-2016-8858

Published: Dec 09, 2016 | Modified: May 17, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
5.8 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Ubuntu
NEGLIGIBLE

The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that OpenSSH upstream does not consider this as a security issue.

Affected Software

Name Vendor Start Version End Version
Openssh Openbsd 6.8 (including) 6.8 (including)
Openssh Openbsd 6.9 (including) 6.9 (including)
Openssh Openbsd 7.0 (including) 7.0 (including)
Openssh Openbsd 7.1 (including) 7.1 (including)
Openssh Openbsd 7.2 (including) 7.2 (including)
Openssh Openbsd 7.3 (including) 7.3 (including)
Openssh Ubuntu esm-infra-legacy/trusty *
Openssh Ubuntu esm-infra/xenial *
Openssh Ubuntu precise *
Openssh Ubuntu precise/esm *
Openssh Ubuntu trusty *
Openssh Ubuntu trusty/esm *
Openssh Ubuntu vivid/stable-phone-overlay *
Openssh Ubuntu vivid/ubuntu-core *
Openssh Ubuntu xenial *
Openssh Ubuntu yakkety *

References