The OpenSSH 9.1 double free: introduced in one release and fixed in the next
A pre-authentication double free in sshd, present only in OpenSSH 9.1. Its short life is the reason it matters less than its severity suggests, and the reason it is worth knowing which release you are on.
A fixed package version is available on 3 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.
What it actually is
sshd 9.1 freed the same memory twice while handling the key exchange algorithm list a client sends. That list arrives before authentication, so the code path is reachable by anyone who can connect.
What an attacker gets: A memory corruption primitive before login. Turning that into code execution was not demonstrated, and the sandbox the unprivileged sshd process runs in makes it considerably harder.
When it applies to you, and when it does not
An old package version and a real exposure are different things. These are the conditions this one needs.
- Only OpenSSH 9.1 introduced it and 9.2 fixed it. Almost no distribution shipped 9.1 in a stable release, which is why several of the releases below have no advisory for it at all.
- The affected code runs in the sandboxed, unprivileged pre-auth process, not in the root parent.
Check your own server
sshd -V 2>&1 | head -1If the upstream version is not 9.1, this one was never yours to worry about.
Fixed package version, per distribution
From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.
| Release | Source package | State | Fixed in |
|---|---|---|---|
| Ubuntu 22.04 LTS | openssh | No advisory names it | no advisory for this release names it |
| Ubuntu 24.04 LTS | openssh | No advisory names it | no advisory for this release names it |
| Debian 12 (bookworm) | openssh | Fixed | 1:9.2p1-1 |
| Debian 13 (trixie) | openssh | Fixed | 1:9.2p1-1 |
| Rocky Linux 9 | openssh | No advisory names it | no advisory for this release names it |
| AlmaLinux 9 | openssh | Fixed | 8.7p1-29.el9_2 |
Install the fix with apt update && apt install --only-upgrade openssh-server openssh-client on Debian and Ubuntu, or dnf update openssh-server openssh-clients on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.
What SecAI has recorded about it
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."
Recorded from nvd. Its weakness class is CWE-415, from NVD.
- http://www.openwall.com/lists/oss-security/2023/02/13/1
- http://www.openwall.com/lists/oss-security/2023/02/22/1
- http://www.openwall.com/lists/oss-security/2023/02/22/2
- http://www.openwall.com/lists/oss-security/2023/02/23/3
- http://www.openwall.com/lists/oss-security/2023/03/06/1
- http://www.openwall.com/lists/oss-security/2023/03/09/2
Read next
Check whether this vulnerability affects your Linux server
One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2023-25136 included. It changes nothing.