OpenSSH OpenSSH是OpenSSH组织的一个安全管理连接的软件。 OpenSSH存在缓冲区错误漏洞,该漏洞源于清理GSSAPI指示器时缺少尾部NULL终止符导致的堆越界读取,可能导致远程攻击者在特定配置下使SSH认证路径崩溃或中止,导致拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:9.9p1-25.el10_2< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:9.9p1-9.el9_8< * |
unaffected |
0:9.9p1-9.el9_8< * |
unaffected | ||
| Red Hat | Red Hat Hardened Images | 10.3p1-6.hum1< * |
unaffected |
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Update Infrastructure 5 | 1786435483< * |
unaffected |
1786533529< * |
unaffected | ||
1787135742< * |
unaffected | ||
1787241260< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:9.9p1-25.el10_2 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:9.9p1-9.el9_8 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:9.9p1-9.el9_8 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Hardened Images | 10.3p1-6.hum1 ~ * |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1786435483 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1786533529 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1787135742 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Update Infrastructure 5 | 1787241260 ~ * |
cpe:/a:redhat:rhui:5::el9
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11807 | 9.6 CRITICAL | Eda-server: websocket missing authorization allows credential theft via activation_id spoo |
| CVE-2026-12112 | 7.8 HIGH | Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse |
| CVE-2026-10609 | 6.8 MEDIUM | Openshift/cluster-logging-operator: cluster logging operator creates and forwards servicea |
| CVE-2026-11820 | 6.5 MEDIUM | Community.general: community.general nexmo — api credentials exposed in get url query stri |
| CVE-2026-9073 | 6.2 MEDIUM | Foreman-mcp-server: mcp server: insecure sensitive http header sanitization |
| CVE-2026-11819 | 5.5 MEDIUM | Community.general: community.general keyring_info — os keyring passphrase returned in plai |
| CVE-2026-12969 | 5.3 MEDIUM | Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation |
| CVE-2026-55655 | 5.0 MEDIUM | Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat ente |
| CVE-2026-12892 | 4.4 MEDIUM | Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.2 |
| CVE-2026-55653 | 4.3 MEDIUM | Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path du |
| CVE-2026-12891 | 4.3 MEDIUM | Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: global buffer overflow (oob read) in |
No comments yet