CVE Vulnerabilities

CVE-2026-106555

Incorrect Resource Transfer Between Spheres

Published: Oct 06, 2026 | Modified: Oct 06, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.

Weakness

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Affected Software

NameVendorStart VersionEnd Version
Openssh-ssh1Ubuntudevel*
Openssh-ssh1Ubuntuesm-apps/bionic*
Openssh-ssh1Ubuntuesm-apps/focal*
Openssh-ssh1Ubuntuesm-apps/jammy*
Openssh-ssh1Ubuntuesm-apps/noble*
Openssh-ssh1Ubuntuesm-apps/resolute*
Openssh-ssh1Ubuntujammy*
Openssh-ssh1Ubuntunoble*
Openssh-ssh1Ubunturesolute*
Openssh-ssh1Ubuntuupstream*

References