#1143924 openssh: CVE-2026-55654

Package:
src:openssh
Source:
src:openssh
Submitter:
Moritz Mühlenhoff
Date:
2026-08-30 18:51:04 UTC
Severity:
normal
Tags:
#1143924#5
Date:
2026-08-08 15:29:37 UTC
From:
To:
Hi,

The following vulnerability was published for openssh.

CVE-2026-55654[0]:
| A flaw was found in OpenSSH. This vulnerability, a heap out-of-
| bounds read, occurs during the cleanup of GSSAPI (Generic Security
| Service Application Programming Interface) indicators when a
| trailing NULL termination is missing in the auth-indicators array. A
| remote attacker, under specific configurations involving GSSAPI
| authentication and a Kerberos environment, could exploit this to
| cause the SSH authentication path to crash or abort. This leads to a
| denial of service (DoS), impacting the availability of the SSH
| service.

This is an issue in the gssapi patch set, for which Red Hat shipped
an update: https://bugzilla.redhat.com/show_bug.cgi?id=2462493

TTBOMK Red Hat is the canonical upstream for the openssh/gssapi
patches and with Debian also shipping support we're probably
also affected?


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-55654
https://www.cve.org/CVERecord?id=CVE-2026-55654

Please adjust the affected versions in the BTS as needed.

#1143924#10
Date:
2026-08-27 14:18:26 UTC
From:
To:
Hi,

Now that there is openssh-gssapi, should we reassign this bug to
src:openssh-gssapi as the GSS_API authentication and key exchange
support was droppend in src:openssh/1:10.4p1-5 ?

If you agree to do so, we can simply reassign and move the bug
reference for the security-tracker to the right source package.

Regards,
Salvatore

#1143924#15
Date:
2026-08-27 15:17:35 UTC
From:
To:
I was holding off on doing so since I assume that what the security team
mainly needs to track is stable releases, and those are all still
openssh.  What do you think?

#1143924#20
Date:
2026-08-27 15:32:17 UTC
From:
To:
Thanks for considering that! But we predominantly operate on the data stored
in the Securiy Tracker, which tracks this across the rename correctly, so
for the BTS you can safely reassign.

Cheers,
        Moritz

#1143924#29
Date:
2026-08-28 07:01:55 UTC
From:
To:
Hi Colin, hi Moritz,

Thank you both. So I have reassigned the bug  and moved the number in
the security-tracker associating it with src:openssh-gssapi.

https://security-tracker.debian.org/tracker/CVE-2026-55654

schould soon reflect the appropriate tracking.

Regards,
Salvatore