Database/Kernel, userspace & hypervisor

OpenSSH (client): Machine-in-the-middle against the client when VerifyHostKeyDNS is enabled
CVSS 6.8CVE-2025-26465Kernel, userspace & hypervisorcurated
Impact
Machine-in-the-middle against the client when VerifyHostKeyDNS is enabled
Who can reach it
Unauthenticated network (MITM)
What to do
Package update; no reboot. Audit client configs for VerifyHostKeyDNS
References
Related entries
- Xen AMD-Vi (AMD IOMMU) interrupt remapping table handling: On AMD-Vi platforms Xen used a single interrupt remappingCVE-2013-0153 · Xen AMD-Vi (AMD IOMMU) interrupt remapping table handlingMedium
- Linux kernel (eBPF verifier): kernel/bpf/verifier.c mishandles pointer types - unprivileged BPF to local rootCVE-2022-23222 · Linux kernel (eBPF verifier)Medium
- Linux kernel (nf_tables): Cross-table use-after-free in nf_tables leading to local privilege escalationCVE-2022-2586 · Linux kernel (nf_tables)Medium
- Xen (x86 PV): Insufficient care with non-coherent mappings - PV guest to host compromiseCVE-2022-26363 · Xen (x86 PV)Medium
- Linux kernel (drivers/pci/pcie): The ASPM link state keeps a raw pointer to function 0 of a multi-function device.CVE-2023-53446 · Linux kernel (drivers/pci/pcie)Medium
- Intel oneAPI Math Kernel Library (oneMKL): An uncontrolled library search path: the component loads a shared libraryCVE-2024-21766 · Intel oneAPI Math Kernel Library (oneMKL)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.