logoalt Hacker News

mr_mitmyesterday at 12:31 PM0 repliesview on HN

Here is a recent example. Currently unpatched in Debian stable.

https://www.cve.org/CVERecord?id=CVE-2026-60002

As I understood this, a malicious server can change its host key somewhere during key exchange and trigger a use-after-free in the client, which might be exploitable for code execution.