PT-2025-40940 · Openbsd+10 · Openssh+10
David Leadbeater
·
Published
2025-10-06
·
Updated
2026-04-06
·
CVE-2025-61985
CVSS v3.1
3.6
Low
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSSH versions prior to 10.1
Description
OpenSSH contains a flaw where the '0' character within an ssh:// URI can be processed, potentially leading to code execution when a
ProxyCommand is utilized. This occurs because the presence of a null byte allows for manipulation of the command execution process.Recommendations
Update to OpenSSH version 10.1 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Centos
Debian
Ibm Aix
Linuxmint
Openssh
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu