Vulnerability record · CVE-2023-25136 · published 3 February 2023
CVE-2023-25136: OpenSSH sshd double-free in kex_algorithms handling
Openbsd · Openssh
OpenSSH server (sshd) 9.1 introduced a double-free during options.kex_algorithms handling, fixed in OpenSSH 9.2. The flaw is reachable by an unauthenticated remote attacker in the default configuration and can be used to jump to an arbitrary location in the sshd address space.
Description
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Automated analysis
high priorityUnauthenticated remote reachability in the default configuration plus a very high EPSS score and public exploit references outweigh the medium CVSS base score.
What it is
OpenSSH server (sshd) 9.1 introduced a double-free during options.kex_algorithms handling, fixed in OpenSSH 9.2. The flaw is reachable by an unauthenticated remote attacker in the default configuration and can be used to jump to an arbitrary location in the sshd address space.
Impact
An attacker can corrupt sshd memory and redirect execution to an arbitrary address, with one third-party report stating remote code execution is theoretically possible. The CVSS vector rates confidentiality as none, integrity as low and availability as high.
Attack surface
Reached over the network against the sshd listener; the CVSS vector shows no privileges required and no user interaction. No authentication is needed because the flaw is in pre-auth key exchange option handling.
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.89685 (99.78th percentile) and multiple references are tagged Exploit, including a public proof-of-concept writeup. No ransomware groups are documented using it.
What to do
- Upgrade OpenSSH to 9.2 or later, or apply the vendor patch for your distribution.
- For OpenBSD 7.2, apply patch 017_sshd.patch.sig.
- If immediate patching is not possible, restrict network access to sshd to trusted management networks.
- Track vendor advisories for Fedora and NetApp products listed as affected.
Detection
- Monitor sshd logs for crashes, abnormal termination or restart loops that could indicate a double-free trigger.
- Watch for repeated pre-authentication connection attempts or malformed key exchange negotiation from single sources.
- Use host-based memory integrity or crash telemetry on sshd processes to catch control-flow anomalies.
- Alert on unexpected child process creation or outbound connections from the sshd service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-25136 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-25136), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.