← Vulnerability feed

Vulnerability record · CVE-2006-5051 · published 27 September 2006

CVE-2006-5051: OpenSSH signal handler race condition double-free

Openbsd · Openssh

OpenSSH before 4.4 contains a signal handler race condition that leads to a double-free. It allows remote attackers to crash the daemon and, when GSSAPI authentication is enabled, possibly execute arbitrary code. The flaw is old but widely deployed versions may still be in use.

8.1 CVSS 3.1 High EPSS 45% · top 1.3% CWE-415 · Double free
8.1CVSS 3.1 base score, v2 9.3
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
116References
16 Jun 2026Last modified by NVD

Description

Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote unauthenticated crash with a possible code execution path and a very high EPSS score, though exploitation requires a race and GSSAPI enabled.

What it is

OpenSSH before 4.4 contains a signal handler race condition that leads to a double-free. It allows remote attackers to crash the daemon and, when GSSAPI authentication is enabled, possibly execute arbitrary code. The flaw is old but widely deployed versions may still be in use.

Impact

An unauthenticated remote attacker can cause a denial of service by crashing sshd, and where GSSAPI authentication is enabled may achieve arbitrary code execution in the sshd process.

Attack surface

Reachable over the network against the SSH service (AV:N, PR:N, UI:N); no authentication or user interaction is required. Exploitation complexity is rated high (AC:H) because it depends on winning a signal handler race, and code execution additionally requires GSSAPI authentication to be enabled.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.44963, 98.7th percentile), but the references are advisories, release notes and mailing lists with no public exploit tag.

What to do

  • Upgrade OpenSSH to 4.4 or later, or apply the vendor patch for your distribution.
  • If immediate upgrade is not possible, disable GSSAPI authentication in sshd_config to remove the code execution path.
  • Restrict SSH exposure to trusted networks and rate-limit or block repeated connection attempts.
  • Monitor vendor advisories for Debian, Apple and OpenBSD packages and apply their backported fixes.

Detection

  • Alert on sshd crashes or unexpected restarts, especially repeated ones from the same source.
  • Correlate sshd core dumps or abnormal termination logs with inbound SSH connection bursts.
  • Monitor for unusual child processes or outbound connections spawned by sshd.
  • Track SSH authentication failures and connection churn from single source IPs as a race attempt indicator.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:22.openssh.asc Broken Link
ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc Broken Link
http://docs.info.apple.com/article.html?artnum=305214 Broken Link
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html Mailing List
http://lists.freebsd.org/pipermail/freebsd-security/2006-October/004051.html Mailing List
http://marc.info/?l=openssh-unix-dev&m=115939141729160&w=2 Mailing List
http://openssh.org/txt/release-4.4 Release Notes
http://secunia.com/advisories/22158 Broken LinkVendor Advisory
http://secunia.com/advisories/22173 Broken LinkVendor Advisory
http://secunia.com/advisories/22183 Broken LinkVendor Advisory
http://secunia.com/advisories/22196 Broken LinkVendor Advisory
http://secunia.com/advisories/22208 Broken LinkVendor Advisory
http://secunia.com/advisories/22236 Broken LinkVendor Advisory
http://secunia.com/advisories/22245 Broken LinkVendor Advisory
http://secunia.com/advisories/22270 Broken LinkVendor Advisory
http://secunia.com/advisories/22352 Broken LinkVendor Advisory
http://secunia.com/advisories/22362 Broken LinkVendor Advisory
http://secunia.com/advisories/22487 Broken LinkVendor Advisory
http://secunia.com/advisories/22495 Broken Link
http://secunia.com/advisories/22823 Broken LinkVendor Advisory
http://secunia.com/advisories/22926 Broken LinkVendor Advisory
http://secunia.com/advisories/23680 Broken LinkVendor Advisory
http://secunia.com/advisories/24479 Broken LinkVendor Advisory
http://secunia.com/advisories/24799 Broken LinkVendor Advisory
http://secunia.com/advisories/24805 Broken LinkVendor Advisory
http://security.freebsd.org/advisories/FreeBSD-SA-06%3A22.openssh.asc Third Party Advisory
http://security.gentoo.org/glsa/glsa-200611-06.xml Third Party Advisory
http://securitytracker.com/id?1016940 Broken LinkThird Party AdvisoryVDB Entry
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.592566 Broken Link
http://sourceforge.net/forum/forum.php?forum_id=681763 Broken Link
http://support.avaya.com/elmodocs2/security/ASA-2006-216.htm Third Party Advisory
http://www-unix.globus.org/mail_archive/security-announce/2007/04/msg00000.html Broken Link
http://www.arkoon.fr/upload/alertes/36AK-2006-07-FR-1.0_FAST360_OPENSSH.pdf Broken Link
http://www.arkoon.fr/upload/alertes/43AK-2006-09-FR-1.0_SSL360_OPENSSH.pdf Broken Link
http://www.debian.org/security/2006/dsa-1189 Mailing List
http://www.debian.org/security/2006/dsa-1212 Broken Link
http://www.kb.cert.org/vuls/id/851340 Third Party AdvisoryUS Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2006:179 Third Party Advisory
http://www.novell.com/linux/security/advisories/2006_62_openssh.html Broken Link
http://www.openbsd.org/errata.html#ssh Release Notes

Track CVE-2006-5051 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2006-5051), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.