Description
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-6887-1 | OpenSSH vulnerability |
References
History
Tue, 04 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 29 Jan 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-04T16:12:30.897Z
Reserved: 2024-07-02T00:00:00.000Z
Link: CVE-2024-39894
Updated: 2024-08-02T04:33:11.961Z
Status : Deferred
Published: 2024-07-02T18:15:03.710
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-39894
OpenCVE Enrichment
Updated: 2025-07-12T22:31:08Z
Ubuntu USN