CVE-2026-62949
Description
A flaw was found in AsyncSSH, a Python package for SSHv2 protocol implementation. A malicious SSH server or an authenticated client can exploit this vulnerability by sending a specially crafted SSH packet with a zero-sized maximum packet size. This can cause the AsyncSSH event loop to freeze, leading to a Denial of Service (DoS) for all current and future connections handled by the process.
Statement
A denial of service vulnerability was found in AsyncSSH, a Python asynchronous SSHv2 client and server implementation. Prior to version 2.24.0, the _process_channel_open and _process_channel_open_confirmation functions in asyncssh/connection.py accept a peer supplied send_pktsize value of zero. When channel data is processed by SSHChannel._flush_send_buf in asyncssh/channel.py, the zero value causes an infinite loop where each iteration attempts to slice and remove zero bytes without reducing the send window, leaving the synchronous loop permanently active with no await point. A malicious SSH server can trigger the client path through SSH_MSG_CHANNEL_OPEN_CONFIRMATION before the first channel write, while an authenticated client can trigger the server path through SSH_MSG_CHANNEL_OPEN, freezing the entire asyncio event loop and rendering all current and future connections handled by the process unresponsive. This issue affects Red Hat Ceph Storage components that use vulnerable versions of asyncssh. The issue is fixed in asyncssh 2.24.0.
Mitigation
Until updates are available, administrators can implement the following mitigations to reduce the risk of event loop freeze attacks:
1. Restrict SSH connectivity for Ceph management and orchestration tools to trusted SSH servers only. Use firewall rules or network policies to prevent connections to untrusted or internet-exposed SSH servers.
2. If using asyncssh-based SSH servers, implement authentication and connection rate limiting to prevent abuse from authenticated attackers attempting to freeze the service.
3. Monitor Ceph management processes for unexpected hangs or unresponsive behavior, and implement automated health checks that can detect and restart frozen processes.
4. Consider using OpenSSH instead of asyncssh for critical management operations where feasible, as OpenSSH is not affected by this vulnerability.
5. For automation scripts using asyncssh, implement connection timeouts and process monitoring to detect and recover from hung connections.
Apply updates as they become available from Red Hat product teams.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 6.5 | N/A | 6.5 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | Low | N/A | Low |
| Privileges Required | Low | N/A | Low |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | None | N/A | None |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Amplification
An infinite loop will cause unexpected consumption of resources, such as CPU cycles or memory. The software's operation may slow down, or cause a long time to respond.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.