{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_security_advisory","csaf_version":"2.1","title":"Pre-authentication Denial of Service attack in OpenSSH","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2025-00009","status":"final","version":"12","initial_release_date":"2025-07-10T19:00:00+00:00","current_release_date":"2026-07-28T02:21:54.494882+00:00","revision_history":[{"date":"2025-07-10T19:00:00+00:00","number":"12","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2025-00009"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2025-26466"}],"notes":[{"category":"summary","text":"A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.","title":"Summary"}]},"product_tree":{"branches":[{"category":"vendor","name":"WatchGuard","branches":[{"category":"product_name","name":"Fireware OS (Default)","branches":[{"category":"product_version_range","name":"vers >= 12.0.0, < 12.11.3","product":{"name":"Fireware OS (Default) vers >= 12.0.0, < 12.11.3","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"}}]},{"category":"product_name","name":"Secure Wi-Fi","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"Secure Wi-Fi all versions","product_id":"CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8"}}]},{"category":"product_name","name":"Dimension","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"Dimension all versions","product_id":"CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"}}]}]}]},"vulnerabilities":[{"notes":[{"category":"description","text":"A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A malicious client may keep sending such packages, leading to an uncontrolled increase in memory consumption on the server side. Consequently, the server may become unavailable, resulting in a denial of service attack.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"],"known_not_affected":["CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8","CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"]},"cve":"CVE-2025-26466","remediations":[{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.11.3 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"]}]}]}