Skip to content

Fix a critical vulnerability that could lead to system dumping and in…#679

Closed
MrSecurityGuy wants to merge 1 commit into
openssh:masterfrom
MrSecurityGuy:patch-1
Closed

Fix a critical vulnerability that could lead to system dumping and in…#679
MrSecurityGuy wants to merge 1 commit into
openssh:masterfrom
MrSecurityGuy:patch-1

Conversation

@MrSecurityGuy
Copy link
Copy Markdown

…fo disclosure via ssh -X

A vulnerability that dates back to 1999 that led to a null crash vulnerability causing info disclosure from a crash dump file from an unauthenticated user when you try ssh-X to connect to a server. someone running a malicious ssh server can trigger this by sending SSH2_MSG_CHANNEL_OPEN(x11) before the client sends x11-req, causing strlen(NULL) in x11_open_helper(). ... Leading to key's being leaked, an potential system hijack.

NULL Pointer Dereference → SIGSEGV → Information Disclosure → Key Theft → RCE

exploit.py

…fo disclosure via ssh -X

A vulnerability that dates back to 1999 that led to a null crash vulnerability causing info disclosure from a crash dump file from an unauthenticated user when you try ssh-X to connect to a server.
someone running a malicious ssh server can trigger this by sending SSH2_MSG_CHANNEL_OPEN(x11) before the client sends x11-req, causing strlen(NULL) in x11_open_helper().
... Leading to key's being leaked, an potential system hijack.

NULL Pointer Dereference → SIGSEGV → Information Disclosure → Key Theft → RCE
@djmdjm
Copy link
Copy Markdown
Contributor

djmdjm commented May 31, 2026

Thanks, I've committed a fix in a1dd1c8 but none of the consequences you list of a simple local crash are true. There is no information disclosure, let alone key theft or RCE possible from this bug.

@djmdjm djmdjm closed this May 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants