CVE-2025-61984
Rocky Linux vulnerability analysis and mitigation

Overview

CVE-2025-61984 affects OpenSSH versions before 10.1, discovered in October 2025. The vulnerability allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources include the command line and %-sequence expansion of a configuration file (NVD, OpenSSH Release Notes).

Technical details

The vulnerability stems from insufficient input validation where control characters in usernames were not properly filtered when passed via the commandline or expanded using %-sequences from the configuration file. This could allow an attacker to inject shell expressions that may be executed when the proxy command is started. The vulnerability has a CVSS v3.1 Base Score of 3.6 (Low) with vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N (NVD, Security Blog).

Impact

The vulnerability can result in Remote Code Execution (RCE) under specific conditions. However, the impact is considered moderate as it requires particular configurations and depends on the user having specific ProxyCommand settings that use the %r expansion token. The main attack vector is through git submodules, where a malicious username configured in the main module's .gitmodules file could trigger the vulnerability (Security Blog).

Exploitability

The vulnerability is exploitable when a user has a particular SSH configuration using ProxyCommand with %r argument and clones a malicious git repository with submodules. The exploit works by forcing a syntax error in the shell command execution, which can lead to arbitrary code execution. Different shells (bash, fish, csh/tcsh) are affected differently, while zsh appears to be resistant to the exploit (Security Blog).

Mitigation and workarounds

The primary mitigation is to upgrade to OpenSSH version 10.1 or later, which disallows control characters in usernames. Alternative mitigations include changing any ProxyCommand in SSH client configuration that passes the %r expansion token to quote it with single quotes. For git users, it's recommended to configure git to turn off SSH transports for submodules using 'git config --global protocol.ssh.allow user'. Additionally, disabling URL handlers for ssh:// can provide additional protection (Security Blog, OpenSSH Release Notes).

Community reactions

The vulnerability was discovered and reported by David Leadbeater, with acknowledgments from the OpenSSH team. The OpenSSH developers considered this a minor security issue, as reflected in their release notes and the low CVSS score. The fix was quickly implemented and released as part of OpenSSH 10.1 (OpenSSH Release Notes, OSS Security).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

openssh: 1:9.2p1-2+deb12u8

Fixed

sid

openssh: 1:10.1p1-1

Fixed

trixie

openssh: 1:10.0p1-7+deb13u1

Fixed

Ubuntu

Fixed

bionic (esm-infra)

openssh

Affected

bionic (fips-updates)

openssh

Unknown

bionic (fips)

openssh

Unknown

devel

openssh: 1:10.2p1-2ubuntu1

Fixed

focal (esm-infra)

openssh: 1:8.2p1-4ubuntu0.13+esm1

Fixed

focal (fips-updates)

openssh: 1:8.2p1-4ubuntu0.fips.0.13.1

Fixed

focal (fips)

openssh

Affected

jammy

openssh: 1:8.9p1-3ubuntu0.14

Fixed

RHEL / CentOS

Fixed

OpenShift

openshift/ose-rhel-coreos-8

Affected

RHEL 8

:appstream:openssh-0:8.0p1-27.el8_10.src

Fixed

RHEL 9

:appstream:openssh-0:8.7p1-13.el9_0.1.src

Fixed

RHEL 10

openssh-0:9.9p1-7.el10_0.1.src

Fixed

Alpine

Fixed

edge

openssh: 10.1_p1-r0

Fixed

v3.22

openssh: 10.0_p1-r10

Fixed

v3.23

openssh: 10.1_p1-r0

Fixed

SourceThis report was generated using AI

Related Rocky Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18922CRITICAL9.8
  • Rocky Linux logoRocky Linux
  • 389-ds-base-snmp-debuginfo
NoYesSep 07, 2026
CVE-2026-44950CRITICAL9.5
  • Rocky Linux logoRocky Linux
  • libXfont-debuginfo
NoYesSep 10, 2026
CVE-2026-59679CRITICAL9.2
  • Rocky Linux logoRocky Linux
  • libXfont2-doc
NoYesSep 10, 2026
CVE-2026-18453HIGH7.5
  • Rocky Linux logoRocky Linux
  • 389-ds:1.4::389-ds-base
NoYesSep 07, 2026
CVE-2026-18355HIGH7.5
  • Rocky Linux logoRocky Linux
  • 389-ds-base-snmp
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management