Use-After-Free Vulnerability in OpenSSH Remote Forwarding Operations
CVE-2026-73282

4.8MEDIUM

Key Information:

Vendor

OpenBSD

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73282?

A vulnerability exists in OpenSSH that allows a use-after-free condition during the realloc of data when particular remote-forwarding operations are executed concurrently. This flaw could potentially be exploited by an attacker to manipulate memory and possibly gain unauthorized access, thus compromising the security and integrity of the affected system. It's crucial for users running versions prior to 10.5 to seek immediate updates and review their configurations to mitigate potential risks.

Affected Version(s)

OpenSSH 0 < 10.5

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.