Database/Kernel, userspace & hypervisor

OpenSSH (sshd): Pre-auth memory/CPU amplification - denial of service against sshd
CVSS 5.9CVE-2025-26466Kernel, userspace & hypervisorcurated
Impact
Pre-auth memory/CPU amplification - denial of service against sshd
Who can reach it
Unauthenticated network
What to do
Package update + sshd restart; rate-limit with PerSourcePenalties
References
Related entries
- OpenSSH (sshd): regreSSHion: signal-handler race in sshd giving unauthenticated remote root on glibc LinuxCVE-2024-6387 · OpenSSH (sshd)High
- Linux kernel (drivers/pci/endpoint/functions): When BAR allocation fails, the endpoint test function frees the backingCVE-2025-38069 · Linux kernel (drivers/pci/endpoint/functions)Medium
- Linux kernel (drivers/iommu): An unaligned DMA mapping with no aligned middle section calls into the mapper with lengthCVE-2026-53164 · Linux kernel (drivers/iommu)Medium
- OpenSSL: CMP servers cache rejected extraCerts forever, letting a client drive the process to OOMCVE-2026-63074 · OpenSSL CMP server (extraCerts cache in a reused OSSL_CMP_CTX)Medium
- strongSwan: expired pointer dereference in PKCS#7 parsing crashes the IKE daemonCVE-2026-78123 · strongSwan openssl plugin (PKCS#7 parsing)Medium
- Linux kernel (ALSA usb-audio): Out-of-bounds access for Extigy/Mbox devicesCVE-2024-53197 · Linux kernel (ALSA usb-audio)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.