{"id":"ECHO-03ea-a4eb-03cb","summary":"Heap out-of-bounds read during cleanup of the GSSAPI \"auth-indicators\"\narray (missing trailing NULL). This array is part of Red Hat's downstream\nGSSAPI authentication-indicators patch and is scoped by upstream to \"Red Hat\nEnterprise Linux versions of OpenSSH\". Echo builds from Debian openssh\n1:10.4p1-1 (sid), which does not carry that patch: gss-serv.c, auth2-gss.c\nand gss-genr.c contain zero references to auth indicators, so the vulnerable\ncode path is not present. Debian rates it undetermined/unimportant.\nhttps://security-tracker.debian.org/tracker/CVE-2026-55654\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2462493\n","modified":"2026-09-15T03:34:27.448857268Z","published":"2026-06-23T20:13:57.906Z","withdrawn":"2026-07-16T11:45:02.611Z","upstream":["CVE-2026-55654"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-55654"}],"affected":[{"package":{"name":"openssh","ecosystem":"Echo","purl":"pkg:deb/echo/openssh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:10.4p1-1+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-03ea-a4eb-03cb.json"}}],"schema_version":"1.9.0"}