原文链接:OpenSSH fixes flaws that enable man-in-the-middle, DoS attacks
“SSH sessions can be a prime target for attackers aiming to intercept credentials or hijack sessions,” researchers from Qualys who found the flaws wrote in their report. “If compromised, hackers could view or manipulate sensitive data, move across multiple critical servers laterally, and exfiltrate valuable information such as database credentials. Such breaches can lead to reputational damage, violate compliance mandates (e.g., GDPR, HIPAA, PCI-DSS), and potentially disrupt critical operations by forcing system downtime to contain the threat.”
The man-in-the-middle vulnerability, tracked as CVE-2025-26465, was introduced in the code over 10 years ago in December 2014. As such it impacts all OpenSSH versions from 6.8p1 through 9.9p1.
The second vulnerability is tracked as CVE-2025-26466 and impacts versions 9.5p1 through 9.9p1. Users are advised to upgrade to the newly released OpenSSH 9.9p2 as soon as it becomes available in their Linux distribution.
第一个漏洞可追溯至2014年12月,影响从6.8p1到9.9p1的所有OpenSSH版本;第二个漏洞影响了9.5p1到9.9p1版本。建议用户在Linux发行版中推出OpenSSH 9.9p2后立即升级到该版本。
