Database/Kernel, userspace & hypervisor

OpenSSH: heap out-of-bounds read during GSSAPI indicator cleanup crashes the authentication path
Impact
A missing NULL terminator in the auth-indicators array leads to a heap out-of-bounds read while sshd cleans up GSSAPI indicators, aborting the authentication process. On hosts configured for GSSAPI/Kerberos authentication this is a remote availability hit on the one service operators use to reach a node - losing sshd on a GPU node means losing the path used to drain jobs, collect logs, and reset the box, which then costs an out-of-band or BMC-console trip. Only the per-connection authentication path is affected, so it is a denial of service rather than a route to code execution. Hosts that do not enable GSSAPIAuthentication in a Kerberos realm are not exposed.
Who can reach it
A remote, unauthenticated attacker who can open a TCP connection to sshd, but only on hosts where GSSAPIAuthentication is enabled and a Kerberos environment is configured. Exploitation conditions are described as specific to that configuration.
What to do
Apply the vendor OpenSSH update (Red Hat shipped RHSA-2026:36759, RHSA-2026:47756, RHSA-2026:47757 and RHSA-2026:54387 for the affected RHEL streams and Hardened Images) and restart sshd; existing sessions survive the restart. As an interim mitigation on nodes that do not need it, set GSSAPIAuthentication no and reload sshd.
References
Related entries
- strongSwan: PKCS#7 certificate enumeration in the openssl plugin leaks memoryCVE-2026-78124 · strongSwan openssl plugin (PKCS#7 certificate enumeration)Low
- OpenSSH ssh-agent: locking bypass lets a forwarded remote session add tokens and use keysCVE-2026-73281 · OpenSSH ssh-agent (agent locking vs session-bind@openssh.com extension)Low
- Linux kernel mlx5_ib (create QP response): mlx5_ib_create_qp_resp is never initialized in create_qp_common, so creatingCVE-2018-20855 · Linux kernel mlx5_ib (create QP response)Low
- Xen on AMD Family 17h / Hygon Family 18h - guest SSBD selection: Setting Speculative Store Bypass Disable on AMD FamilyCVE-2022-42336 · Xen on AMD Family 17h / Hygon Family 18h - guest SSBD selectionLow
- SSSD autofs responder: improper buffer offset during request parsing causes out-of-bounds read and crashCVE-2026-104029 · SSSD autofs responder (request buffer offset calculation)Low
- OpenSSH sshd: restrict keyword in authorized_keys did not cover tunnel forwardingCVE-2026-73283 · OpenSSH sshd (authorized_keys restrict keyword vs tunnel forwarding)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.