Database/Kernel, userspace & hypervisor

OpenSSH: no maximum packet length check when decompressing highly compressed data
Impact
sshd and ssh before 10.6 do not enforce the maximum packet length while decompressing, so a peer can hand over a small compressed payload that expands far beyond the intended limit. The record scores this as partial integrity and availability impact, reachable over the network with no authentication, which makes it the most exposed of the 10.6 set: sshd is the one daemon that is listening on every management interface, bastion host and GPU node in the fleet. On a GPU cluster the practical worry is memory pressure or an sshd that stops answering on nodes that are only reachable by SSH, which turns a routine job into a console or BMC recovery. No code execution is claimed in the record.
Who can reach it
Anyone who can open a TCP connection to sshd, before authentication. The client side is also affected when connecting to a hostile or compromised server.
What to do
Upgrade OpenSSH to 10.6 (or the distribution backport) and restart sshd. Existing sessions survive an sshd restart, so this is a package update plus daemon restart with no node drain or reboot; schedule it fleet-wide rather than per node.
References
Related entries
- Linux kernel (drivers/vfio/pci/xe): Resetting a passed-through Intel GPU virtual function that does not supportCVE-2026-31601 · Linux kernel (drivers/vfio/pci/xe)Medium
- Linux kernel (net/xfrm): The async-event reply buffer was sized without accounting for the interface-ID attribute, soCVE-2026-43107 · Linux kernel (net/xfrm)Medium
- Linux kernel (drivers/iommu/amd): AMD-Vi hands out the completion-wait sequence number outside the IOMMU lock, soCVE-2026-43220 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (net/xfrm): Tearing down an IPTFS security association cancels its hrtimers while holding the very locksCVE-2026-53197 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/smc): Setsockopt() on an SMC socket copies the option value from user memory while holding the socketCVE-2026-53274 · Linux kernel (net/smc)Medium
- OpenSSH client: double free on attacker-controlled DH-GEX parameters crashes the client in FIPS modeCVE-2026-55653 · OpenSSH client (DH-GEX known-group validation in FIPS mode)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.