HomeSecurityOpenSSH flaws expose SSH servers to MiTM and DoS attacks

OpenSSH flaws expose SSH servers to MiTM and DoS attacks

OpenSSH has released security updates that fix two major vulnerabilities: a man-in-the-middle (MitM) and a denial-of-service (DoS). Notably, one of these flaws remained unpatched for over ten years.

See also: Russian cyberspies breached their target via Wi-Fi connection

OpenSSH flaw

Qualys identified the two flaws and presented their exploit capabilities to OpenSSH maintainers.

OpenSSH (Open Secure Shell) is a free, open source solution that implements the SSH (Secure Shell) protocol. It provides encrypted communication, ensuring secure remote access, file transfer, and tunneling over insecure networks.

It is one of the most widely used tools worldwide, with wide adoption on Linux and Unix systems (such as BSD and macOS). It is used extensively in enterprise environments, IT, DevOps, cloud computing and cybersecurity applications, thanks to its reliability and flexibility.

The MiTM vulnerability, known as CVE-2025-26465, first appeared in December 2014 with the release of OpenSSH 6.8p1. However, the issue went unnoticed for more than ten years, highlighting the importance of continuous monitoring and evaluation of software security.

This flaw affects OpenSSH users when the "VerifyHostKeyDNS" option is enabled, creating opportunities for MitM attacks by malicious actors. When enabled, due to improper error handling, an attacker can trick the client into accepting a malicious server's key by forcing an out-of-memory error during verification.

See also: Flaw in qBittorrent exposes users to MitM attacks for 14 years

By intercepting an SSH connection and presenting an oversized SSH key with excessive certificate extensions, an attacker can cause the client to run out of memory, bypass host authentication, and hijack the session. This allows them to intercept credentials, execute commands, and extract sensitive data.

OpenSSH flaws expose SSH servers to MiTM and DoS attacks

The "VerifyHostKeyDNS" setting is disabled by default in OpenSSH. However, in FreeBSD it remained enabled by default for a decade, from 2013 to 2023, which left many systems vulnerable to this type of attack.

The second flaw is CVE-2025-26466, a denial of service vulnerability , introduced in OpenSSH 9.5p1, released in August 2023.

The issue arises from an uncontrolled memory allocation during the key exchange process, which leads to excessive resource consumption. An attacker can repeatedly send small 16-byte ping messages, forcing OpenSSH to store 256-byte responses, without any immediate limitations.

During the key exchange process, these responses are stored permanently, resulting in excessive memory consumption and CPU. This can lead to significant slowdowns or even possible system failures.

The impact of exploiting CVE-2025-26466 may not be as severe as the first flaw. However, the fact that it can be exploited before authentication is complete makes it extremely dangerous, significantly increasing the risk of downtime.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: BlastRADIUS: Vulnerability in RADIUS protocol allows MitM attacks

Man-in-the-Middle (MiTM) attacks are a type of cyberattack where a malicious actor interferes with the communication between two parties without their knowledge. The attacker can intercept, modify, or even manipulate the data being exchanged, compromising the security or confidentiality of the information. Common targets for such attacks include Wi-Fi networks , websites without SSL, and communications that do not use modern encryption methods.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS