← Vulnerability feed

Vulnerability record · CVE-2023-25136 · published 3 February 2023

CVE-2023-25136: OpenSSH sshd double-free in kex_algorithms handling

Openbsd · Openssh

OpenSSH server (sshd) 9.1 introduced a double-free during options.kex_algorithms handling, fixed in OpenSSH 9.2. The flaw is reachable by an unauthenticated remote attacker in the default configuration and can be used to jump to an arbitrary location in the sshd address space.

6.5 CVSS 3.1 Medium EPSS 90% · top 0.2% CWE-415 · Double free
6.5CVSS 3.1 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
32References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote reachability in the default configuration plus a very high EPSS score and public exploit references outweigh the medium CVSS base score.

What it is

OpenSSH server (sshd) 9.1 introduced a double-free during options.kex_algorithms handling, fixed in OpenSSH 9.2. The flaw is reachable by an unauthenticated remote attacker in the default configuration and can be used to jump to an arbitrary location in the sshd address space.

Impact

An attacker can corrupt sshd memory and redirect execution to an arbitrary address, with one third-party report stating remote code execution is theoretically possible. The CVSS vector rates confidentiality as none, integrity as low and availability as high.

Attack surface

Reached over the network against the sshd listener; the CVSS vector shows no privileges required and no user interaction. No authentication is needed because the flaw is in pre-auth key exchange option handling.

Exploitation

Not listed in CISA KEV, but EPSS is very high at 0.89685 (99.78th percentile) and multiple references are tagged Exploit, including a public proof-of-concept writeup. No ransomware groups are documented using it.

What to do

  • Upgrade OpenSSH to 9.2 or later, or apply the vendor patch for your distribution.
  • For OpenBSD 7.2, apply patch 017_sshd.patch.sig.
  • If immediate patching is not possible, restrict network access to sshd to trusted management networks.
  • Track vendor advisories for Fedora and NetApp products listed as affected.

Detection

  • Monitor sshd logs for crashes, abnormal termination or restart loops that could indicate a double-free trigger.
  • Watch for repeated pre-authentication connection attempts or malformed key exchange negotiation from single sources.
  • Use host-based memory integrity or crash telemetry on sshd processes to catch control-flow anomalies.
  • Alert on unexpected child process creation or outbound connections from the sshd service account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2023/02/13/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/02/22/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/02/22/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/02/23/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/03/06/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/03/09/2 Mailing ListThird Party Advisory
https://bugzilla.mindrot.org/show_bug.cgi?id=3522 ExploitIssue TrackingThird Party Advisory
https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/017_sshd.patch.sig PatchVendor Advisory
https://github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946 PatchThird Party Advisory
https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/ ExploitThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JGAUIXJ3TEKCRKVWFQ6GDAG
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7LKQDFZWKYHQ65TBSH2X2H
https://news.ycombinator.com/item?id=34711565 Issue TrackingThird Party Advisory
https://security.gentoo.org/glsa/202307-01 Third Party Advisory
https://security.netapp.com/advisory/ntap-20230309-0003/ Third Party Advisory
https://www.openwall.com/lists/oss-security/2023/02/02/2 ExploitMailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/02/13/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/02/22/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/02/22/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/02/23/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/03/06/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/03/09/2 Mailing ListThird Party Advisory
https://bugzilla.mindrot.org/show_bug.cgi?id=3522 ExploitIssue TrackingThird Party Advisory
https://ftp.openbsd.org/pub/OpenBSD/patches/7.2/common/017_sshd.patch.sig PatchVendor Advisory
https://github.com/openssh/openssh-portable/commit/486c4dc3b83b4b67d663fb0fa62bc24138ec3946 PatchThird Party Advisory
https://jfrog.com/blog/openssh-pre-auth-double-free-cve-2023-25136-writeup-and-proof-of-concept/ ExploitThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JGAUIXJ3TEKCRKVWFQ6GDAG
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7LKQDFZWKYHQ65TBSH2X2H
https://news.ycombinator.com/item?id=34711565 Issue TrackingThird Party Advisory
https://security.gentoo.org/glsa/202307-01 Third Party Advisory
https://security.netapp.com/advisory/ntap-20230309-0003/ Third Party Advisory
https://www.openwall.com/lists/oss-security/2023/02/02/2 ExploitMailing ListThird Party Advisory

Track CVE-2023-25136 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2023-25136), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.