Bug 2543853 (CVE-2026-94029)

Summary: CVE-2026-94029 org.apache.sshd/sshd-sftp: Apache MINA SSHD: Denial of Service via memory exhaustion in SFTP check-file extension
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: ewittman, fmariani, fmongiar, gbenhaim, gmalinko, janstey, jnethert, jwon, mcarlett, nipatil, niyer, pantinor, pdelbell, pjindal, rkubis, rstepani, tcunning, twaugh, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Apache MINA SSHD. When processing SSH File Transfer Protocol (SFTP) check-file extensions, the server accumulates file hash verification responses entirely in memory without enforcing a size limit. An authenticated remote attacker can exploit this vulnerability by requesting file verification with a minimal block size on a large file, leading to memory exhaustion and a Denial of Service (DoS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-30 09:47:14 UTC
Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH.




Using a very small "block size" (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes. The resulting SFTP reply message was accumulated fully in memory server-side, which could, with a suitably large (possibly sparse) file exhaust the server-side memory, taking down the server.




Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply. Many SFTP implementations have a general limit on the size of SFTP messages anyway; typically 256kB as in OpenSSH or also in Apache MINA SSHD.