Database/Kernel, userspace & hypervisor

OpenSSH (transport): Terrapin: prefix-truncation attack on the SSH Binary Packet Protocol
CVSS 5.9CVE-2023-48795Kernel, userspace & hypervisorcurated
Impact
Terrapin: prefix-truncation attack on the SSH Binary Packet Protocol - silently downgrades channel integrity
Who can reach it
Unauthenticated network (MITM position)
What to do
Package update on both ends + sshd restart; no reboot
References
Related entries
- Linux kernel (drivers/pci): The DOE state machine signals the caller's completion before destroying the work_structCVE-2023-54235 · Linux kernel (drivers/pci)Medium
- OpenSSH (sshd): Pre-auth memory/CPU amplification - denial of service against sshdCVE-2025-26466 · OpenSSH (sshd)Medium
- Linux kernel (drivers/pci/endpoint/functions): When BAR allocation fails, the endpoint test function frees the backingCVE-2025-38069 · Linux kernel (drivers/pci/endpoint/functions)Medium
- Linux kernel (drivers/iommu): An unaligned DMA mapping with no aligned middle section calls into the mapper with lengthCVE-2026-53164 · Linux kernel (drivers/iommu)Medium
- OpenSSL: CMP servers cache rejected extraCerts forever, letting a client drive the process to OOMCVE-2026-63074 · OpenSSL CMP server (extraCerts cache in a reused OSSL_CMP_CTX)Medium
- strongSwan: expired pointer dereference in PKCS#7 parsing crashes the IKE daemonCVE-2026-78123 · strongSwan openssl plugin (PKCS#7 parsing)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.