{"id":"UBUNTU-CVE-2026-55654","details":"A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.","modified":"2026-09-11T20:51:50.103054539Z","published":"2026-06-23T04:17:00Z","upstream":["CVE-2026-55654"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-55654"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-55654"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-55654"}],"affected":[{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-8","1:7.5p1-9","1:7.5p1-9build1","1:7.5p1-10"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client-ssh1","binary_version":"1:7.5p1-10"}],"priority_reason":"This is a low severity issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55654.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-11build1"],"ecosystem_specific":{"binaries":[{"binary_version":"1:7.5p1-11build1","binary_name":"openssh-client-ssh1"}],"priority_reason":"This is a low severity issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55654.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-12","1:7.5p1-12build1","1:7.5p1-13"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client-ssh1","binary_version":"1:7.5p1-13"}],"priority_reason":"This is a low severity issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55654.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-14","1:7.5p1-15","1:7.5p1-15build1","1:7.5p1-16"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client-ssh1","binary_version":"1:7.5p1-16"}],"priority_reason":"This is a low severity issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55654.json"}},{"package":{"name":"openssh","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/openssh?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:9.9p1-3ubuntu3","1:9.9p1-3ubuntu3.1","1:10.0p1-5ubuntu2","1:10.0p1-5ubuntu3","1:10.0p1-5ubuntu4","1:10.0p1-5ubuntu5","1:10.0p1-5ubuntu5.1","1:10.0p1-5ubuntu5.4"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client","binary_version":"1:10.0p1-5ubuntu5.4"},{"binary_name":"openssh-client-gssapi","binary_version":"1:10.0p1-5ubuntu5.4"},{"binary_version":"1:10.0p1-5ubuntu5.4","binary_name":"openssh-server"},{"binary_name":"openssh-server-gssapi","binary_version":"1:10.0p1-5ubuntu5.4"},{"binary_name":"openssh-sftp-server","binary_version":"1:10.0p1-5ubuntu5.4"},{"binary_version":"1:10.0p1-5ubuntu5.4","binary_name":"openssh-tests"},{"binary_name":"ssh","binary_version":"1:10.0p1-5ubuntu5.4"},{"binary_version":"1:10.0p1-5ubuntu5.4","binary_name":"ssh-askpass-gnome"}],"priority_reason":"This is a low severity issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55654.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-17"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client-ssh1","binary_version":"1:7.5p1-17"}],"priority_reason":"This is a low severity issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55654.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-17","1:7.5p1-18"],"ecosystem_specific":{"binaries":[{"binary_version":"1:7.5p1-18","binary_name":"openssh-client-ssh1"}],"priority_reason":"This is a low severity issue"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55654.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"low"}]}