← Back to browse · API

CVE-2016-8858

Severity
HIGH
CVSS
7.5
EPSS
0.29462
Risk score
40.31
CISA KEV
No
PoC
No
Published
2016-12-09
Modified
2026-05-29
First seen
2026-08-07
Aliases
EUVD-2016-9683, GHSA-CFX4-R6F2-M2MC
Products
n/a:n/a n/a
Sources
euvd EUVD-2016-9683

Description

The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that "OpenSSH upstream does not consider this as a security issue."

References