CVE-2026-93996 Apache MINA SSHD 拒绝服务漏洞
影响攻击者可耗尽内存导致应用崩溃
Apache MINA SSHD 的 sshd-scp 组件在实现 SCP 协议时未限制协议行长度。恶意对端可发送不含换行符的超长命令,使接收方持续分配内存,最终触发 OutOfMemoryError 导致应用崩溃。
影响范围
Apache MINA SSHD 2.19.0 及以下版本,以及 3.0.0-M1 至 3.0.0-M5 版本。
漏洞详情
该漏洞属于不受控资源消耗(拒绝服务)。SCP 协议以 LF 结尾的行传输命令,而 sshd-scp 的处理程序未对行长度设置上限。攻击者只需发送一段永不出现 LF 的垃圾命令,接收方就会不断分配内存存储该命令,直至内存耗尽。
利用条件与风险
利用前提是攻击者能与目标建立 SCP 会话并发送恶意数据,无需认证即可触发,实战中可造成服务不可用。
修复建议
官方建议升级至 2.20.0 或 3.0.0-M6 版本,该版本通过限制 SCP 协议行长度修复此问题;暂无其他公开缓解措施。
Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH.
Component sshd-scp of Apache MINA SSHD provides a Java implementation of SCP. The SCP command protocol is line-oriented with LF-terminated lines. The protocol handler in sshd-scp did not impose any limit on the length of such protocol lines. A malicious peer just sending a junk command containing a never-ending sequence of characters but never a LF would cause the receiver to allocate memory to store this whole junk command, exhausting memory and crashing the application with an OutOfMemoryError.
Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by enforcing an upper limit on the length of SCP protocol lines.