CVE-2023-25136 is a double-free vulnerability in the OpenSSH server daemon (sshd) introduced in OpenSSH 9.1 and fixed in OpenSSH 9.2. The flaw occurs during handling of options.kex_algorithms in the backwards-compatibility key exchange path, where a pointer can be freed twice during pre-authentication processing. Because the vulnerable code is reachable before user authentication, a remote unauthenticated attacker can trigger memory corruption by interacting with the SSH service. The vulnerability affects the sshd address space and has been assessed as potentially allowing control-flow redirection to an attacker-chosen location within that address space, with denial of service confirmed and remote code execution considered theoretically possible.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a minimal proof-of-concept (PoC) for CVE-2023-25136, a double free vulnerability in OpenSSH 9.1p1's pre-authentication phase. The repository contains three files: a Dockerfile to build a vulnerable OpenSSH 9.1p1 environment (with seccomp sandbox disabled for easier observation of the crash), a README.md with detailed setup and usage instructions, and poc.py, a Python script using paramiko to connect to the target SSH server and send a crafted handshake. The PoC is designed to trigger a double free in the server's pre-authentication child process, resulting in a denial of service (DoS) as the process crashes. The exploit is not intended for remote code execution, and the README notes that exploitation beyond DoS is considered highly difficult. The main attack vector is network-based, targeting the SSH service on a specified IP and port (default 127.0.0.1:2222). The repository is well-structured for local testing and research purposes.
This repository provides two Python scripts for scanning and exploiting the OpenSSH 9.1 pre-auth double-free vulnerability (CVE-2023-25136). The first script, 'openssh-9_1.py', allows the user to supply a file containing a list of IP addresses. It iterates through each IP, attempting to connect via SSH using the paramiko library with a custom client version string, and reports whether each target is vulnerable. The second script, 'openssh-9_1-single_exploit.py', targets a single IP address provided by the user and attempts the same exploit. Both scripts are proof-of-concept and do not provide post-exploitation capabilities such as shell access. The repository includes a README with usage instructions, requirements, and background information on the vulnerability. No hardcoded endpoints are present; all targets are user-supplied. The attack vector is network-based, targeting SSH services on OpenSSH 9.1 servers.
This repository provides a proof-of-concept (PoC) exploit for CVE-2023-25136, a double-free vulnerability in OpenSSH 9.1p1. The repository contains three files: a LICENSE, a README.md with usage instructions, and the main exploit script 'cve-2023-25136.py'. The exploit is written in Python and uses the 'paramiko' library to connect to a target SSH server. By setting a custom SSH client version string and initiating a connection, the script triggers the double-free bug in the target OpenSSH server, resulting in a denial-of-service (crash/abort). The script is a simple PoC and does not provide remote code execution or privilege escalation; its sole purpose is to demonstrate the vulnerability by crashing the server. The only fingerprintable endpoint is the target IP address, which defaults to 127.0.0.1 but should be set to the actual vulnerable server. The exploit is operational as a DoS tool and is not weaponized for further exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.