Post #1874941
2026-04-09 21:04 UTC
#Debian once again introduced a security flaw to #OpenSSH with their custom patches applied to Debian OpenSSH packages 🥳
"Jeremy Brown discovered a flaw in the GSSAPI Key Exchange patch applied in Debian to OpenSSH, an implementation of the SSH protocol suite, affecting non-default configurations with the GSSAPIKeyExchange setting enabled. A remote attacker can take advantage of this flaw to cause a denial of service, or potentially the execution of arbitrary code."
https://lists.debian.org/debian-security-announce/2026/msg00114.html
#itsecurity
Replies (1)
-
@dboehmer@ieji.de 2026-04-09 21:06
Who still remembers the #Debian RNG patch disaster?? https://nvd.nist.gov/vuln/detail/cve-2008-0166 I just realized this will very soon be 18 (eighteen) years ago! 😲 Feeling old yet?