Vulnerability record · CVE-2006-5051 · published 27 September 2006
CVE-2006-5051: OpenSSH signal handler race condition double-free
Openbsd · Openssh
OpenSSH before 4.4 contains a signal handler race condition that leads to a double-free. It allows remote attackers to crash the daemon and, when GSSAPI authentication is enabled, possibly execute arbitrary code. The flaw is old but widely deployed versions may still be in use.
Description
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote unauthenticated crash with a possible code execution path and a very high EPSS score, though exploitation requires a race and GSSAPI enabled.
What it is
OpenSSH before 4.4 contains a signal handler race condition that leads to a double-free. It allows remote attackers to crash the daemon and, when GSSAPI authentication is enabled, possibly execute arbitrary code. The flaw is old but widely deployed versions may still be in use.
Impact
An unauthenticated remote attacker can cause a denial of service by crashing sshd, and where GSSAPI authentication is enabled may achieve arbitrary code execution in the sshd process.
Attack surface
Reachable over the network against the SSH service (AV:N, PR:N, UI:N); no authentication or user interaction is required. Exploitation complexity is rated high (AC:H) because it depends on winning a signal handler race, and code execution additionally requires GSSAPI authentication to be enabled.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.44963, 98.7th percentile), but the references are advisories, release notes and mailing lists with no public exploit tag.
What to do
- Upgrade OpenSSH to 4.4 or later, or apply the vendor patch for your distribution.
- If immediate upgrade is not possible, disable GSSAPI authentication in sshd_config to remove the code execution path.
- Restrict SSH exposure to trusted networks and rate-limit or block repeated connection attempts.
- Monitor vendor advisories for Debian, Apple and OpenBSD packages and apply their backported fixes.
Detection
- Alert on sshd crashes or unexpected restarts, especially repeated ones from the same source.
- Correlate sshd core dumps or abnormal termination logs with inbound SSH connection bursts.
- Monitor for unusual child processes or outbound connections spawned by sshd.
- Track SSH authentication failures and connection churn from single source IPs as a race attempt indicator.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5051 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5051), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.