CVE-2016-8858
7.5 HIGHThe kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory c...
Published: 2016-12-09 · Last updated: 2026-05-29
Severity and scoring
- CVSS
- 7.5 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE
- CWE-399, CWE-400
Affected products
| Vendor | Product |
|---|---|
| openbsd | openssh |
Description
The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that "OpenSSH upstream does not consider this as a security issue."
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2016-8858
- [Vendor advisory]http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/kex.c.diff?r1=1.126&r2=1.127&f=h
- [Vendor advisory]http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/kex.c?rev=1.127&content-type=text/x-cvsweb-markup
- [Other]http://www.openwall.com/lists/oss-security/2016/10/19/3
- [Other]http://www.openwall.com/lists/oss-security/2016/10/20/1
- [Other]http://www.securityfocus.com/bid/93776
- [Other]http://www.securitytracker.com/id/1037057
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=1384860
- [Other]https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- [Patch]https://ftp.openbsd.org/pub/OpenBSD/patches/6.0/common/013_ssh_kexinit.patch.sig
- [Patch]https://github.com/openssh/openssh-portable/commit/ec165c392ca54317dbe3064a8c200de6531e89ad
- [Other]https://security.FreeBSD.org/advisories/FreeBSD-SA-16:33.openssh.asc
- [Other]https://security.gentoo.org/glsa/201612-18
- [Other]https://security.netapp.com/advisory/ntap-20180201-0001/
- [Vendor advisory]http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/kex.c.diff?r1=1.126&r2=1.127&f=h
- [Vendor advisory]http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/kex.c?rev=1.127&content-type=text/x-cvsweb-markup
- [Other]http://www.openwall.com/lists/oss-security/2016/10/19/3
- [Other]http://www.openwall.com/lists/oss-security/2016/10/20/1
- [Other]http://www.securityfocus.com/bid/93776
- [Other]http://www.securitytracker.com/id/1037057
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=1384860
- [Other]https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- [Patch]https://ftp.openbsd.org/pub/OpenBSD/patches/6.0/common/013_ssh_kexinit.patch.sig
- [Patch]https://github.com/openssh/openssh-portable/commit/ec165c392ca54317dbe3064a8c200de6531e89ad
- [Other]https://security.FreeBSD.org/advisories/FreeBSD-SA-16:33.openssh.asc
- [Other]https://security.gentoo.org/glsa/201612-18
- [Other]https://security.netapp.com/advisory/ntap-20180201-0001/
Related CVEs
Same vendor
- CVE-2026-3497 — Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions (7.5 HIGH)
- CVE-2023-51767 — OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer ... (7.0 HIGH)
- CVE-2023-51384 — In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied (5.5 MEDIUM)
- CVE-2023-28531 — ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints (9.8 CRITICAL)
- CVE-2023-25136 — OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling (6.5 MEDIUM)
Same CWE
- CVE-2026-47734 — Dulwich is a pure-Python implementation of the Git file formats and protocols (5.7 MEDIUM)
- CVE-2026-46689 — Kanidm is an identity management platform
- CVE-2026-46679 — libp2p is a JavaScript Implementation of libp2p networking stack (7.5 HIGH)
- CVE-2026-46522 — ImageMagick is free and open-source software used for editing and manipulating digital images (7.5 HIGH)
- CVE-2026-45783 — libp2p is a JavaScript Implementation of libp2p networking stack (7.5 HIGH)