{"id":"CVE-2019-16905","details":"OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.","modified":"2026-07-08T05:54:56.249741679Z","published":"2019-10-09T20:15:23.503Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"3.2.7"}],"source":"CPE_RANGE","vendor_product":"siemens:scalance_x204rna_ecc_firmware","cpes":["cpe:2.3:o:siemens:scalance_x204rna_ecc_firmware:*:*:*:*:*:*:*:*"]},{"vendor_product":"siemens:scalance_x204rna_firmware","cpes":["cpe:2.3:o:siemens:scalance_x204rna_firmware:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"3.2.7"}],"source":"CPE_RANGE"}]},"references":[{"type":"ADVISORY","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf"},{"type":"ADVISORY","url":"https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshkey-xmss.c"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201911-01"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20191024-0003/"},{"type":"ADVISORY","url":"https://www.openssh.com/releasenotes.html"},{"type":"ADVISORY","url":"https://www.openwall.com/lists/oss-security/2019/10/09/1"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1153537"},{"type":"FIX","url":"https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshkey-xmss.c.diff?r1=1.5&r2=1.6&f=h"},{"type":"EVIDENCE","url":"https://ssd-disclosure.com/archives/4033/ssd-advisory-openssh-pre-auth-xmss-integer-overflow"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssh/openssh-portable","events":[{"introduced":"a0349a1cc4a18967ad1dbff5389bcdf9da098814"},{"last_affected":"aede1c34243a6f7feae2fb2cb686ade5f9be6f3d"},{"introduced":"fd0fa130ecf06d7d092932adcd5d77f1549bfc8d"},{"fixed":"cdf1d0a9f5d18535e0a18ff34860e81a6d83aa5c"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.7"},{"last_affected":"7.9"},{"introduced":"8.0"},{"fixed":"8.1"}]}}],"versions":["V_8_0_P1","V_7_9_P1","V_7_8_P1","V_7_7_P1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-16905.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}