CVE-2016-8858

HIGH

OpenSSH <7.4 - DoS

Title source: llm
STIX 2.1

Description

The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that "OpenSSH upstream does not consider this as a security issue."

Exploits (1)

nomisec WORKING POC 7 stars
by dag-erling · poc
https://github.com/dag-erling/kexkill

Scores

CVSS v3 7.5
EPSS 0.2687
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-399
Status published
Products (6)
openbsd/openssh 6.8
openbsd/openssh 6.9
openbsd/openssh 7.0
openbsd/openssh 7.1
openbsd/openssh 7.2
openbsd/openssh 7.3
Published Dec 09, 2016
Tracked Since Feb 18, 2026