OpenSSH OpenSSH是OpenSSH组织的一个安全管理连接的软件。 OpenSSH存在资源管理错误漏洞,该漏洞源于Diffie-Hellman Group Exchange客户端路径存在双重释放漏洞,在FIPS模式已知组验证期间处理攻击者控制的DH-GEX组参数时发生,成功利用会导致客户端进程终止,造成拒绝服务。以下版本受到影响:Red Hat Enterprise Linux 10、Red Hat Enterprise Linux 6、Red Hat Enterprise Linux 7、Re
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:9.9p1-25.el10_2< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | 0:8.0p1-30.el8_10< * |
unaffected |
0:8.0p1-30.el8_10< * |
unaffected | ||
| Red Hat | Red Hat Enterprise Linux 9 | 0:9.9p1-9.el9_8< * |
unaffected |
0:9.9p1-9.el9_8< * |
unaffected | ||
| Red Hat | Red Hat Hardened Images | 10.3p1-6.hum1< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Update Infrastructure 5 | 1786435483< * |
unaffected |
1786533529< * |
unaffected | ||
1787135742< * |
unaffected | ||
1787241260< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:9.9p1-25.el10_2 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 8 | 0:8.0p1-30.el8_10 ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 8 | 0:8.0p1-30.el8_10 ~ * |
cpe:/a:redhat:enterprise_linux:8::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:9.9p1-9.el9_8 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:9.9p1-9.el9_8 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Hardened Images | 10.3p1-6.hum1 ~ * |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1786435483 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1786533529 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1787135742 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1787241260 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11807 | 9.6 CRITICAL | Eda-server: websocket missing authorization allows credential theft via activation_id spoo |
| CVE-2026-12112 | 7.8 HIGH | Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse |
| CVE-2026-10609 | 6.8 MEDIUM | Openshift/cluster-logging-operator: cluster logging operator creates and forwards servicea |
| CVE-2026-11820 | 6.5 MEDIUM | Community.general: community.general nexmo — api credentials exposed in get url query stri |
| CVE-2026-9073 | 6.2 MEDIUM | Foreman-mcp-server: mcp server: insecure sensitive http header sanitization |
| CVE-2026-11819 | 5.5 MEDIUM | Community.general: community.general keyring_info — os keyring passphrase returned in plai |
| CVE-2026-12969 | 5.3 MEDIUM | Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation |
| CVE-2026-55655 | 5.0 MEDIUM | Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat ente |
| CVE-2026-12892 | 4.4 MEDIUM | Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.2 |
| CVE-2026-12891 | 4.3 MEDIUM | Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: global buffer overflow (oob read) in |
| CVE-2026-55654 | 3.7 LOW | Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi in |
No comments yet