{"id":"CVE-2023-25136","details":"OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states \"remote code execution is theoretically possible.\"","modified":"2026-08-12T13:34:00.330927Z","published":"2023-02-03T00:00:00Z","related":["ALSA-2023:2645","CGA-mqg9-f766-j25c"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25136.json"},"references":[{"type":"WEB","url":"https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/017_sshd.patch.sig"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=34711565"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2023/02/02/2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25136.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JGAUIXJ3TEKCRKVWFQ6GDAGQFTIIGQQP/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7LKQDFZWKYHQ65TBSH2X2HJQ4V2THS3/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25136"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202307-01"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230309-0003/"},{"type":"REPORT","url":"https://bugzilla.mindrot.org/show_bug.cgi?id=3522"},{"type":"FIX","url":"https://github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/02/13/1"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/02/22/1"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/02/22/2"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/02/23/3"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/03/06/1"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/03/09/2"},{"type":"ARTICLE","url":"https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssh/openssh-portable","events":[{"introduced":"0ffb46f2ee2ffcc4daf45ee679e484da8fcf338c"},{"fixed":"486c4dc3b83b4b67d663fb0fa62bc24138ec3946"}],"database_specific":{"cpe":"cpe:2.3:a:openbsd:openssh:9.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"9.1"},{"last_affected":"9.1"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["9.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25136.json","vanir_signatures_modified":"2026-08-12T13:34:00Z","vanir_signatures":[{"source":"https://github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946","target":{"function":"compat_kex_proposal","file":"compat.c"},"deprecated":false,"digest":{"function_hash":"118456307265918822993183845344807249614","length":753},"id":"CVE-2023-25136-0ab7c60f","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946","target":{"function":"compat_pkalg_proposal","file":"compat.c"},"deprecated":false,"digest":{"function_hash":"76943240051596031711763984993421529394","length":424},"id":"CVE-2023-25136-3787b0b6","signature_type":"Function","signature_version":"v1"},{"digest":{"length":410,"function_hash":"212652943476130378868419676907070987021"},"id":"CVE-2023-25136-5bfc610e","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946","target":{"file":"compat.c","function":"compat_cipher_proposal"},"deprecated":false},{"target":{"file":"compat.c"},"deprecated":false,"digest":{"line_hashes":["83589648752989715290650839198962214645","329892068102067720888341098580298123240","177513386508925729136292818796922213857","339340910026144685107970787261715577635","144018939557174605213828025937930135706","173484486965340709052335623819764218732","304700631074823457646957735684415154705","227538380910095194226395460534480552986","192948405723392404346714349161667096097","9469493054080965994529429256762026878","55188678287755430717836321076827298802","281306935055482112900686618738551136782","216438549429403703874566747418195123379","180466277492941068128384735429005176493","273709931733691172226080345985406181316","116864435953437300469249507779935097202","238791531932518523761084853534844702814","190140884886759192188872546577334219689","221429695535509130649978337450787482814","269395615482261015947544781182831685041","208251565582124202052792082760227312504","302057517542619678387050950185058444428","203752864320362965429535529904730333242","276292056983437343675349764124793772527","284237610092287733290793395964254761342","242474690308998079289439629701806681948","125131897871234561664724868045677876590","216868530349156713089042009209821144852","122255777631083949403368615143220046131","283912275984244290683230643655027005835","325790611851037684331376571066811609028","305703836663070734070295053392197759849","14438550667141083691881287657591393461","5623584408971955288840573407479474433","109709693131126739710122319347800082964"],"threshold":0.9},"id":"CVE-2023-25136-d9013154","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946"}]}}],"schema_version":"1.9.0"}