The 4th Linux kernel flaw this month can lead to stolen SSH host keys
2026-05-15T20:52:10Z•407ac1d84992c58e99c92978e7e99a35c7f8e8a2b3f160ac572985c138a10ac4
incident-responsekernelkey-rotationlinuxmitigationpatch-availablequalyssshssh-host-keysvulnerability
What happened
ZDNet reports that Qualys disclosed a Linux kernel vulnerability (the fourth kernel flaw reported that month) that can be exploited to steal SSH host private keys. A patch has been released upstream, but fixes are not yet available from all Linux distributors. Operators should apply vendor kernel updates as soon as they are available, treat existing SSH host keys as potentially compromised (rotate/reissue keys and update known_hosts), restrict administrative and SSH access until kernels are patched, and audit systems for signs of compromise.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- zdnet_security
- Record identifier
- 407ac1d84992c58e99c92978e7e99a35c7f8e8a2b3f160ac572985c138a10ac4
- Enrichment time
- 2026-05-15T20:52:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.