CVE-2017-9078: Debian Linux
High severity, CVSS 8.8. EPSS: 5.7% chance of exploitation in the next 30 days.
The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled.
Affected products
- Debian Debian Linux: version 8.0 only
- Dropbear SSH Project Dropbear SSH: before 2017.75 (fixed in 2017.75)
- Netapp h410c Firmware: affected versions not specified
Published 2017-05-19. Last modified 2026-06-17.