CVE-2018-7750: Debian Linux

Critical severity, CVSS 9.8. EPSS: 27.1% chance of exploitation in the next 30 days.

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Paramiko Paramiko: before 1.17.6 (fixed in 1.17.6); from 1.18.0, before 1.18.5 (fixed in 1.18.5); from 2.0.0, before 2.0.8 (fixed in 2.0.8); from 2.1.0, before 2.1.5 (fixed in 2.1.5); from 2.2.0, before 2.2.3 (fixed in 2.2.3); from 2.3.0, before 2.3.2 (fixed in 2.3.2); …
  • Red Hat Ansible Engine: version 2.0 only; version 2.4 only
  • Red Hat Cloudforms: version 4.5 only; version 4.6 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.4 only; version 6.5 only; version 6.6 only
  • Red Hat Enterprise Linux Server Eus: version 6.7 only
  • Red Hat Enterprise Linux Server Tus: version 6.6 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only
  • Red Hat Virtualization: version 4.1 only

Published 2018-03-13. Last modified 2026-06-17.