A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
History

Mon, 03 Mar 2025 18:45:00 +0000


Fri, 28 Feb 2025 13:45:00 +0000

Type Values Removed Values Added
References

Wed, 19 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Feb 2025 14:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 19 Feb 2025 05:30:00 +0000


Tue, 18 Feb 2025 19:45:00 +0000

Type Values Removed Values Added
References

Tue, 18 Feb 2025 18:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
Title Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-390
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2025-02-18T18:27:16.843Z

Updated: 2025-03-12T07:16:38.979Z

Reserved: 2025-02-10T18:31:47.978Z

Link: CVE-2025-26465

cve-icon Vulnrichment

Updated: 2025-03-03T17:48:15.682Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-18T19:15:29.230

Modified: 2025-03-03T18:15:40.247

Link: CVE-2025-26465

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-02-17T00:00:00Z

Links: CVE-2025-26465 - Bugzilla