New OpenSSH Flaws Enable Man-in-the-Middle and DoS Attacks — Patch Now

New OpenSSH Flaws Enable Man-in-the-Middle and DoS Attacks — Patch Now
Summary: Two vulnerabilities were discovered in the OpenSSH suite that could allow a machine-in-the-middle (MitM) attack and a denial-of-service (DoS) attack, jeopardizing network security. These issues affect various versions of the OpenSSH client and server, potentially allowing unauthorized access and service disruption. The vulnerabilities have been patched in the latest release, OpenSSH 9.9p2.

Affected: OpenSSH (versions 6.8p1 to 9.9p1 for CVE-2025-26465 and 9.5p1 to 9.9p1 for CVE-2025-26466)

Keypoints :

  • CVE-2025-26465 allows active MitM attacks if the VerifyHostKeyDNS option is enabled.
  • CVE-2025-26466 allows pre-authentication DoS attacks that can lock out legitimate users.
  • Both vulnerabilities were addressed in the newly released OpenSSH 9.9p2.

Source: https://thehackernews.com/2025/02/new-openssh-flaws-enable-man-in-middle.html