Medium severity6.5NVD Advisory· Published Feb 3, 2023· Updated Jun 17, 2026
CVE-2023-25136
CVE-2023-25136
Description
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
44- cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:500f_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:c250_firmware:-:*:*:*:*:*:*:*
- OpenSSH/OpenSSH serverdescription
- osv-coords34 versionspkg:apk/chainguard/opensshpkg:apk/chainguard/openssh-clientpkg:apk/chainguard/openssh-docpkg:apk/chainguard/openssh-keygenpkg:apk/chainguard/openssh-keyscanpkg:apk/chainguard/openssh-keysignpkg:apk/chainguard/openssh-pam-configpkg:apk/chainguard/openssh-pam-configurationpkg:apk/chainguard/openssh-pkcs11-helperpkg:apk/chainguard/openssh-serverpkg:apk/chainguard/openssh-server-configpkg:apk/chainguard/openssh-servicepkg:apk/chainguard/openssh-sftp-serverpkg:apk/chainguard/openssh-sk-helperpkg:apk/wolfi/opensshpkg:apk/wolfi/openssh-clientpkg:apk/wolfi/openssh-docpkg:apk/wolfi/openssh-keygenpkg:apk/wolfi/openssh-keyscanpkg:apk/wolfi/openssh-keysignpkg:apk/wolfi/openssh-pam-configpkg:apk/wolfi/openssh-pam-configurationpkg:apk/wolfi/openssh-pkcs11-helperpkg:apk/wolfi/openssh-serverpkg:apk/wolfi/openssh-server-configpkg:apk/wolfi/openssh-servicepkg:apk/wolfi/openssh-sftp-serverpkg:apk/wolfi/openssh-sk-helperpkg:rpm/almalinux/opensshpkg:rpm/almalinux/openssh-askpasspkg:rpm/almalinux/openssh-clientspkg:rpm/almalinux/openssh-keycatpkg:rpm/almalinux/openssh-serverpkg:rpm/almalinux/pam_ssh_agent_auth
< 9.2_p1-r0+ 33 more
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 9.2_p1-r0
- (no CPE)range: < 8.7p1-29.el9_2
- (no CPE)range: < 8.7p1-29.el9_2
- (no CPE)range: < 8.7p1-29.el9_2
- (no CPE)range: < 8.7p1-29.el9_2
- (no CPE)range: < 8.7p1-29.el9_2
- (no CPE)range: < 0.10.4-5.29.el9_2
Patches
Vulnerability mechanics
References
16- ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/017_sshd.patch.signvdPatchVendor Advisory
- github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946nvdPatchThird Party Advisory
- bugzilla.mindrot.org/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/nvdExploitThird Party Advisory
- www.openwall.com/lists/oss-security/2023/02/02/2nvdExploitMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2023/02/13/1nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2023/02/22/1nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2023/02/22/2nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2023/02/23/3nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2023/03/06/1nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2023/03/09/2nvdMailing ListThird Party Advisory
- news.ycombinator.com/itemnvdIssue TrackingThird Party Advisory
- security.gentoo.org/glsa/202307-01nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20230309-0003/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JGAUIXJ3TEKCRKVWFQ6GDAGQFTIIGQQP/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7LKQDFZWKYHQ65TBSH2X2HJQ4V2THS3/nvd
News mentions
0No linked articles in our index yet.