CVE-2026-62949
CVE-2026-62949: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-62949] Denial of Service via zero-sized SSH packets
CVE-2026-62949Source published Source updated
Denial of Service via zero-sized SSH packets. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.
- Related products — impact not confirmed
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Source-reported affected versions
- < 2.24.0
- Source-reported fixed versions
- 2.24.0
- Mitigation guidance
- Until updates are available, administrators can implement the following mitigations to reduce the risk of event loop freeze attacks: 1. Restrict SSH connectivity for Ceph management and orchestration tools to trusted SSH servers only. Use firewall rules or network policies to prevent connections to untrusted or internet-exposed SSH servers. 2. If using asyncssh-based SSH servers, implement authentication and connection rate limiting to prevent abuse from authenticated attackers attempting to freeze the service. 3. Monitor Ceph management processes for unexpected hangs or unresponsive behavior, and implement automated health checks that can detect and restart frozen processes. 4. Consider using OpenSSH instead of asyncssh for critical management operations where feasible, as OpenSSH is not affected by this vulnerability. 5. For automation scripts using asyncssh, implement connection timeouts and process monitoring to detect and recover from hung connections. Apply updates as they become available from Red Hat product teams.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.