PT-2023-25414 · Openssh+1 · Openssh+1

Zack Miele

·

Published

2023-07-21

·

Updated

2025-09-24

·

CVE-2023-3603

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSH SFTP server (affected versions not specified)
Description A missing allocation check in the SFTP server when processing read requests can cause a NULL dereference under low-memory conditions. A malicious client can request up to 4GB SFTP reads, leading to the allocation of large buffers without checking for failure. This can likely crash the authenticated user's SFTP server connection, especially in forking-based implementations, and may also cause a Denial of Service (DoS) for legitimate users in thread-based servers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12375
CVE-2023-3603

Affected Products

Openssh
Red Os