Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in libssh automatic certificate-based public key authentication. In ssh_userauth_publickey_auto() in src/auth.c, the iterator over certificate candidates was not advanced correctly when configured certificates were missing or repeatedly rejected by the server. Under specific non-default certificate configurations, this could cause the client to restart the same authentication attempts indefinitely, leading to denial of service.