From b51484f9495099ad6fbeb0b4f77b1d4215963260 Mon Sep 17 00:00:00 2001 From: Xin LI Date: Wed, 2 Nov 2016 06:56:35 +0000 Subject: MFC r308197: MFV r308196: Fix OpenSSH remote Denial of Service vulnerability. Security: CVE-2016-8858 --- crypto/openssh/kex.c | 1 + 1 file changed, 1 insertion(+) (limited to 'crypto') diff --git a/crypto/openssh/kex.c b/crypto/openssh/kex.c index d371f47c48dd..9c9f56228ea5 100644 --- a/crypto/openssh/kex.c +++ b/crypto/openssh/kex.c @@ -468,6 +468,7 @@ kex_input_kexinit(int type, u_int32_t seq, void *ctxt) if (kex == NULL) return SSH_ERR_INVALID_ARGUMENT; + ssh_dispatch_set(ssh, SSH2_MSG_KEXINIT, NULL); ptr = sshpkt_ptr(ssh, &dlen); if ((r = sshbuf_put(kex->peer, ptr, dlen)) != 0) return r; -- cgit v1.2.3