CVE-2025-26465: Debian Linux

Medium severity, CVSS 6.8. EPSS: 7.7% chance of exploitation in the next 30 days.

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

Affected products

  • Debian Debian Linux: version 11.0 only; version 12.0 only
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Ontap: version 9 only
  • OpenBSD OpenSSH: from 6.9, up to and including 9.8; version 6.8 only; version 9.9 only
  • Red Hat Enterprise Linux: version 9.0 only
  • Red Hat Openshift Container Platform: version 4.0 only

Published 2025-02-18. Last modified 2026-09-02.