Direct Vulnerabilities

Known vulnerabilities in the openssh package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Out-of-bounds Read

<0:9.9p1-25.el10_2
  • M
Directory Traversal

<0:9.9p1-25.el10_2
  • M
Double Free

<0:9.9p1-25.el10_2
  • M
Improper Restriction of Communication Channel to Intended Endpoints

<0:9.9p1-25.el10_2
  • H
Expired Pointer Dereference

<0:9.9p1-25.el10_2
  • M
Directory Traversal

<0:10.4p1-1.hum1
  • M
Arbitrary Argument Injection

<0:10.4p1-1.hum1
  • M
Arbitrary Argument Injection

*
  • M
Information Exposure

*
  • M
Improper Restriction of Excessive Authentication Attempts

<0:10.4p1-1.hum1
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • M
Improperly Implemented Security Check for Standard

<0:10.4p1-1.hum1
  • M
Improperly Implemented Security Check for Standard

*
  • H
Expired Pointer Dereference

<0:10.4p1-1.hum1
  • H
Directory Traversal

<0:10.4p1-1.hum1
  • M
Directory Traversal

*
  • M
Missing Initialization of Resource

<0:10.4p1-1.hum1
  • M
Missing Initialization of Resource

*
  • M
Improper Restriction of Excessive Authentication Attempts

<0:10.4p1-1.hum1
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • M
Improper Restriction of Communication Channel to Intended Endpoints

<0:10.3p1-6.hum1
  • M
Double Free

<0:10.3p1-6.hum1
  • L
Out-of-bounds Read

<0:10.3p1-6.hum1
  • L
Misinterpretation of Input

<0:9.9p1-23.el10_2
  • M
Improper Handling of Inconsistent Special Elements

<0:9.9p1-23.el10_2
  • L
Missing Authentication for Critical Function

<0:9.9p1-23.el10_2
  • L
OS Command Injection

<0:9.9p1-23.el10_2
  • H
Improper Preservation of Permissions

<0:9.9p1-23.el10_2
  • L
Misinterpretation of Input

<0:9.9p1-14.el10_1
  • L
Missing Authentication for Critical Function

<0:9.9p1-14.el10_1
  • L
OS Command Injection

<0:9.9p1-14.el10_1
  • M
Improper Handling of Inconsistent Special Elements

<0:9.9p1-14.el10_1
  • H
Improper Preservation of Permissions

<0:9.9p1-14.el10_1
  • L
OS Command Injection

<0:9.9p1-7.el10_0.3
  • L
Missing Authentication for Critical Function

<0:9.9p1-7.el10_0.3
  • H
Improper Preservation of Permissions

<0:9.9p1-7.el10_0.3
  • L
Misinterpretation of Input

<0:9.9p1-7.el10_0.3
  • M
Improper Handling of Inconsistent Special Elements

<0:9.9p1-7.el10_0.3
  • M
Improper Neutralization of Null Byte or NUL Character

<0:10.2p1-9.hum1
  • M
Failure to Sanitize Special Element

<0:10.2p1-9.hum1
  • H
Access of Uninitialized Pointer

<0:10.2p1-9.hum1
  • M
Improper Authentication

<0:10.3p1-2.hum1
  • H
Access of Uninitialized Pointer

<0:9.9p1-7.el10_0.2
  • H
Access of Uninitialized Pointer

<0:9.9p1-13.el10_1
  • M
Improper Neutralization of Null Byte or NUL Character

<0:9.9p1-7.el10_0.1
  • M
Failure to Sanitize Special Element

<0:9.9p1-7.el10_0.1
  • M
Improper Neutralization of Null Byte or NUL Character

<0:9.9p1-12.el10_1
  • M
Failure to Sanitize Special Element

<0:9.9p1-12.el10_1
  • M
Expected Behavior Violation

<0:9.9p1-11.el10
  • M
Information Exposure

*