Impact
SSH in OpenSSH versions prior to 10.4 contains a use‑after‑free bug that is triggered when a server changes its host key during a key exchange. The bug causes the client to dereference a freed memory pointer, resulting in a crash. This vulnerability is mapped to CWE‑416 and CWE‑825 and manifests as a denial‑of‑service condition on the client side.
Affected Systems
The affected component is the OpenBSD OpenSSH client. All installations running a version earlier than 10.4 are vulnerable. Derived packages or distributions that have not updated to 10.4p1 or later share this issue.
Risk and Exploitability
The CVSS score of 7.7 reflects a high severity for a client‑side denial of service. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog, suggesting no widely reported attacks. The likely attack vector is remote; an attacker who can control an SSH server can trigger the fault by changing its host key during a session. Exploitation requires network connectivity to the vulnerable client and the ability to alter the host key on the server side. No known remote code execution path exists.
OpenCVE Enrichment
Ubuntu USN