{"id":"UBUNTU-CVE-2023-25136","details":"OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states \"remote code execution is theoretically possible.\"","modified":"2025-11-25T05:54:35.221080Z","published":"2023-02-03T06:15:00Z","withdrawn":"2025-11-25T05:07:04Z","upstream":["CVE-2023-25136"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-25136"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2023/02/02/2"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2023/02/13/1"},{"type":"REPORT","url":"https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-25136"}],"affected":[{"package":{"name":"openssh","ecosystem":"Ubuntu:Pro:FIPS-updates:18.04:LTS","purl":"pkg:deb/ubuntu/openssh@1:7.9p1-10~ubuntu18.04.fips.0.10?arch=source&distro=fips-updates/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.9p1-10~ubuntu18.04.fips.0.1","1:7.9p1-10~ubuntu18.04.fips.0.2","1:7.9p1-10~ubuntu18.04.fips.0.3","1:7.9p1-10~ubuntu18.04.fips.0.4","1:7.9p1-10~ubuntu18.04.fips.0.5","1:7.9p1-10~ubuntu18.04.fips.0.6","1:7.9p1-10~ubuntu18.04.fips.0.7","1:7.9p1-10~ubuntu18.04.fips.0.8","1:7.9p1-10~ubuntu18.04.fips.0.9","1:7.9p1-10~ubuntu18.04.fips.0.10"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.10"},{"binary_name":"openssh-client-hmac","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.10"},{"binary_name":"openssh-server","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.10"},{"binary_name":"openssh-server-hmac","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.10"},{"binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.10","binary_name":"openssh-sftp-server"},{"binary_name":"openssh-tests","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.10"},{"binary_name":"ssh","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.10"},{"binary_name":"ssh-askpass-gnome","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.10"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-25136.json"}},{"package":{"name":"openssh","ecosystem":"Ubuntu:Pro:FIPS:18.04:LTS","purl":"pkg:deb/ubuntu/openssh@1:7.9p1-10~ubuntu18.04.fips.0.2?arch=source&distro=fips/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.9p1-10~ubuntu18.04.fips.0.1","1:7.9p1-10~ubuntu18.04.fips.0.2"],"ecosystem_specific":{"binaries":[{"binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.2","binary_name":"openssh-client"},{"binary_name":"openssh-client-hmac","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.2"},{"binary_name":"openssh-server","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.2"},{"binary_name":"openssh-server-hmac","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.2"},{"binary_name":"openssh-sftp-server","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.2"},{"binary_name":"openssh-tests","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.2"},{"binary_name":"ssh","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.2"},{"binary_name":"ssh-askpass-gnome","binary_version":"1:7.9p1-10~ubuntu18.04.fips.0.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-25136.json"}},{"package":{"name":"openssh","ecosystem":"Ubuntu:Pro:FIPS-updates:24.04:LTS","purl":"pkg:deb/ubuntu/openssh@1:9.6p1-3ubuntu13.14+Fips1?arch=source&distro=fips-updates/noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:9.6p1-3ubuntu13.7+Fips1","1:9.6p1-3ubuntu13.12+Fips1","1:9.6p1-3ubuntu13.13+Fips1","1:9.6p1-3ubuntu13.14+Fips1"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client","binary_version":"1:9.6p1-3ubuntu13.14+Fips1"},{"binary_name":"openssh-server","binary_version":"1:9.6p1-3ubuntu13.14+Fips1"},{"binary_version":"1:9.6p1-3ubuntu13.14+Fips1","binary_name":"openssh-sftp-server"},{"binary_version":"1:9.6p1-3ubuntu13.14+Fips1","binary_name":"openssh-tests"},{"binary_name":"ssh","binary_version":"1:9.6p1-3ubuntu13.14+Fips1"},{"binary_name":"ssh-askpass-gnome","binary_version":"1:9.6p1-3ubuntu13.14+Fips1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-25136.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"},{"type":"Ubuntu","score":"medium"}]}