GPU VulnDB

Database/Kernel, userspace & hypervisor

OpenSSH sshd: the value "none" is sometimes treated as a filename instead of disabling the feature

CVSS 3.6CVE-2026-106587Kernel, userspace & hypervisorcurated

Impact

Operators write none in sshd_config to switch a feature off; before 10.6 sshd sometimes read it as a path instead. The result is a daemon whose effective configuration differs from the one the operator reviewed and committed, which is exactly the failure mode that config-management and CIS-style hardening baselines are supposed to prevent across a fleet. The record rates it low integrity impact, local vector, high complexity, so the realistic consequence is a control silently not applied on hosts built from a hardening template rather than a direct break-in.

Who can reach it

Local, requiring low privileges per the record. The practical exposure is misconfiguration: any sshd whose config sets an option to none.

What to do

Upgrade to OpenSSH 10.6 and restart sshd. Before and after the upgrade, check the effective configuration with sshd -T on a representative node rather than trusting the file, and confirm that any option set to none is actually disabled. Package update plus daemon restart.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.