Incorrect Expiration Management in OpenSSH Product by OpenSSH
CVE-2026-106584

2.5LOW

Key Information:

Vendor

OpenBSD

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106584?

OpenSSH versions before 10.6 exhibit a vulnerability in ssh-keygen, where certificates may show incorrect expiration times due to mishandling of Daylight Saving Time. This issue can disproportionately affect users in certain Antarctic regions, leading to potential security implications for those relying on accurate time-based certificate validations.

Affected Version(s)

OpenSSH 0 < 10.6

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.