openssh曝光高危漏洞

原文链接:OpenSSH fixes flaws that enable man-in-the-middle, DoS attacks

“SSH sessions can be a prime target for attackers aiming to intercept credentials or hijack sessions,” researchers from Qualys who found the flaws wrote in their report. “If compromised, hackers could view or manipulate sensitive data, move across multiple critical servers laterally, and exfiltrate valuable information such as database credentials. Such breaches can lead to reputational damage, violate compliance mandates (e.g., GDPR, HIPAA, PCI-DSS), and potentially disrupt critical operations by forcing system downtime to contain the threat.”
The man-in-the-middle vulnerability, tracked as CVE-2025-26465, was introduced in the code over 10 years ago in December 2014. As such it impacts all OpenSSH versions from 6.8p1 through 9.9p1.
The second vulnerability is tracked as CVE-2025-26466 and impacts versions 9.5p1 through 9.9p1. Users are advised to upgrade to the newly released OpenSSH 9.9p2 as soon as it becomes available in their Linux distribution.

第一个漏洞可追溯至2014年12月,影响从6.8p1到9.9p1的所有OpenSSH版本;第二个漏洞影响了9.5p1到9.9p1版本。建议用户在Linux发行版中推出OpenSSH 9.9p2后立即升级到该版本。

9 个赞

no……

1 个赞

最讨厌的漏洞,没有之一

1 个赞

绝了,一周前才把老古董升级到9.7p1,真是令人难过 :grimacing:
image

1 个赞

又来了

有点频繁啊

2 个赞

啊这,天哪

1 个赞

这个漏洞只能靠白名单来解决吗?不然天天更新补丁,内网生产环境风险太大了。

1 个赞

内网更新真是太麻烦了,天天要跑客户

1 个赞

Debian 和 ubuntu-server 都还没发更新包?

1 个赞

我们这内网漏洞都不管的,小院高墙。

1 个赞

image
已升级了一台,太麻烦了

1 个赞

好像debian已经有了,ubuntu还没有

1 个赞

已经修复了。
https://security-tracker.debian.org/tracker/CVE-2025-26465

1 个赞

这边一有漏洞就发邮件叫修复,够烦的,这软件 天天都是漏洞

1 个赞

太好了 又有新洞研究了

1 个赞

ubuntu的早修复了, 比如24.04的9.6p1-3ubuntu13.8就已经是修复版本了,只是版本号没有升到9.9p2

1 个赞

那说 9.9p2 这个版本有什么意义?

1 个赞

谢谢提醒

1 个赞

OpenSSH 9.9p2兼容哪个Openssl版本?在官网找了半天没找到,有没有佬知道的。

1 个赞

首先 VerifyHostKeyDNS 默认 false
其次这是个 MITM :frowning:

2 个赞