Heap Out-of-Bounds Read in OpenSSH Affects Remote Authentication Services
CVE-2026-55654
3.7LOW
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 23 June 2026
What is CVE-2026-55654?
A vulnerability was identified in OpenSSH that manifests as a heap out-of-bounds read during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators. This issue arises due to a missing trailing NULL termination in the auth-indicators array. If exploited by a remote attacker, particularly in scenarios where GSSAPI authentication is employed within a Kerberos environment, it has the potential to crash or abort the SSH authentication path. Such an exploit may lead to a denial of service, severely affecting the availability and reliability of the SSH service.
Affected Version(s)
Red Hat Hardened Images 10.3p1-6.hum1