Описание
ELSA-2026-13381: openssh security update (IMPORTANT)
[8.7p1-49.0.1]
- Upstream references found with /usr/bin/ssh [Orabug: 37814929]
- upstream: fix AuthorizedPrincipalsCommand when AuthorizedKeysCommand [Orabug: 37647064]
- Update upstream references [Orabug: 36564626]
[8.7p1-49]
- CVE-2026-35385: Fix privilege escalation via scp legacy protocol when not in preserving file mode Resolves: RHEL-164752
- CVE-2026-35388: Add connection multiplexing confirmation for proxy-mode multiplexing sessions Resolves: RHEL-166249
- CVE-2026-35387: Fix incomplete application of PubkeyAcceptedAlgorithms and HostbasedAcceptedAlgorithms with regard to ECDSA keys Resolves: RHEL-166233
- CVE-2026-35414: Fix mishandling of authorized_keys principals option Resolves: RHEL-166201
- CVE-2026-35386: Add validation rules to usernames and hostnames set for ProxyJump/-J on the commandline Resolves: RHEL-166217
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
openssh
8.7p1-49.0.1.el9_7
openssh-askpass
8.7p1-49.0.1.el9_7
openssh-clients
8.7p1-49.0.1.el9_7
openssh-keycat
8.7p1-49.0.1.el9_7
openssh-server
8.7p1-49.0.1.el9_7
pam_ssh_agent_auth
0.10.4-5.49.0.1.el9_7
Oracle Linux x86_64
openssh
8.7p1-49.0.1.el9_7
openssh-askpass
8.7p1-49.0.1.el9_7
openssh-clients
8.7p1-49.0.1.el9_7
openssh-keycat
8.7p1-49.0.1.el9_7
openssh-server
8.7p1-49.0.1.el9_7
pam_ssh_agent_auth
0.10.4-5.49.0.1.el9_7