CVE-2019-16905 is a pre-authentication integer overflow vulnerability affecting OpenSSH versions 7.7 through 7.9 and 8.x before 8.1, specifically when compiled with an experimental XMSS key type. This flaw, rated High (CVSS 7.8), allows for memory corruption and local code execution due to an error in the XMSS key parsing algorithm. While the potential impact is significant (confidentiality, integrity, and availability), the vulnerability requires a client or server to be configured with a crafted XMSS key, and the XMSS implementation is experimental and not officially supported in portable OpenSSH builds. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.7, <= 7.9CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.1CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:* | ||
< 3.2.7CPE matchmatch criteria | cpe:2.3:o:siemens:scalance_x204rna_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-16905
Sep 8, 2020OpenSSH 7.7 through 7.9 and 8.x before 8.1 when compiled with an experimental key type has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions and there is no supported way to enable it when building portable OpenSSH.
Oct 8, 2019openssh: an integer overflow in the private key parsing code for the XMSS key type
Aug 28, 2019