CVE-2025-26466General(canonical / debian_linux)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • openssh
  • ubuntu_linux

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-02); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
debian_linuxopensshubuntu_linux

10 versions affected across 3 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-02: 1Mentions · 2026-02-20: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-20: 102-0202-20
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-021
General1
2026-02-201
Disclosure1
Full discourse2 posts
  • @pedri77@pedri77
    Disclosure

    Two critical OpenSSH vulnerabilities discovered! Qualys TRU finds client and server flaws (CVE-2025-26465 & CVE-2025-26466) enabling MITM and… https://f.mtr.cool/vvhqednxzz

    Post summary

    Qualys reports two critical OpenSSH client and server vulnerabilities (CVE-2025-26465 & CVE-2025-26466) that can facilitate man‑in‑the‑middle attacks.

    0000073
    2.1K followersView on X
  • athar shah@AthAthar
    General

    OpenSSH vulnerabilities & SSH malware are spiking! (CVE-2025-26466, RCEs, Terrapin). Is your AWS infrastructure truly secure? I help businesses with robust AWS setup & ongoing management, fortifying your cloud against evolving threats. Let's talk security! #AWS#CloudSecurity#SSH

    Post summary

    The message is a marketing note highlighting increased OpenSSH vulnerabilities, including CVE-2025-26466, without providing exploit details, patches, or evidence of active exploitation.

    0000069
    569 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux24.04--
OScanonicalubuntu_linux24.10--
OSdebiandebian_linux11.0--
OSdebiandebian_linux12.0--
OSdebiandebian_linux13.0--
Appopenbsdopenssh9.5--
Appopenbsdopenssh9.6--
Appopenbsdopenssh9.6--
Appopenbsdopenssh9.7--
Appopenbsdopenssh9.7--
Appopenbsdopenssh9.8--
Appopenbsdopenssh9.8--
Appopenbsdopenssh9.9--
Appopenbsdopenssh9.9--

Explore more