PT-2025-23504 · Sslh+1 · Sslh+1

Matthias Gerstner

·

Published

2025-06-02

·

Updated

2025-06-17

·

CVE-2025-46807

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions sslh versions prior to 2.2.4
Description A resource allocation issue without limits or throttling in sslh allows attackers to exhaust file descriptors, denying service to legitimate users. This issue can be exploited to impact user service through resource exhaustion attacks.
Recommendations For versions prior to 2.2.4, update to version 2.2.4 or later to resolve the issue. As a temporary workaround, consider implementing measures to limit resource allocation and prevent exhaustion attacks.

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2026-00160
CVE-2025-46807
OPENSUSE-SU-2025:15194-1

Affected Products

Debian
Sslh