Medium [CVE-2026-62949] Denial of Service via zero-sized SSH packets
This medium-severity Red Hat Linux advisory covers CVE-2026-62949; related products: Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, Red Hat Ceph Storage 9.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
Denial of Service via zero-sized SSH packets. Red Hat rates this moderate (CVSS 6.5).
Weakness: CWE-835.
Affected products named by the advisory: Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.
- < 2.24.0
Official advisory · high-confidence parse· fetched 15 days ago·verify at source
Mitigation checklist
- Until updates are available, administrators can implement the following mitigations to reduce the risk of event loop freeze attacks: 1. Restrict SSH connectivity for Ceph management and orchestration tools to trusted SSH servers only. Use firewall rules or network policies to prevent connections to untrusted or internet-exposed SSH servers. 2. If using asyncssh-based SSH servers, implement authentication and connection rate limiting to prevent abuse from authenticated attackers attempting to freeze the service. 3. Monitor Ceph management processes for unexpected hangs or unresponsive behavior, and implement automated health checks that can detect and restart frozen processes. 4. Consider using OpenSSH instead of asyncssh for critical management operations where feasible, as OpenSSH is not affected by this vulnerability. 5. For automation scripts using asyncssh, implement connection timeouts and process monitoring to detect and recover from hung connections. Apply updates as they become available from Red Hat product teams.
Official advisory · high-confidence parse· fetched 15 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.