CVE-2016-0778: Apple Mac OS X
High severity, CVSS 8.1. EPSS: 20.9% chance of exploitation in the next 30 days.
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
Affected products
- Apple Mac OS X: from 10.9.0, up to and including 10.9.5; from 10.10.0, up to and including 10.10.5; from 10.11.0, up to and including 10.11.3
- HP Virtual Customer Access System: up to and including 15.07
- OpenBSD OpenSSH: version 5.4 only; version 5.5 only; version 5.6 only; version 5.7 only; version 5.8 only; version 5.9 only; …
- Oracle Linux: version 7 only
- Oracle Solaris: version 11.3 only
- Sophos Unified Threat Management Software: version 9.353 only
Published 2016-01-14. Last modified 2026-06-17.