Описание
ELSA-2026-22468: openssh security update (IMPORTANT)
[7.4p1-23.0.5]
- Fix privilege escalation via scp legacy protocol when not in preserving file mode [CVE-2026-35385][Orabug: 39480251]
Обновленные пакеты
Oracle Linux 7
Oracle Linux x86_64
openssh
7.4p1-23.0.5.el7_9
openssh-askpass
7.4p1-23.0.5.el7_9
openssh-cavs
7.4p1-23.0.5.el7_9
openssh-clients
7.4p1-23.0.5.el7_9
openssh-keycat
7.4p1-23.0.5.el7_9
openssh-ldap
7.4p1-23.0.5.el7_9
openssh-server
7.4p1-23.0.5.el7_9
openssh-server-sysvinit
7.4p1-23.0.5.el7_9
pam_ssh_agent_auth
0.10.3-2.23.0.5.el7_9
Связанные CVE
Связанные уязвимости
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
In OpenSSH before 10.3, a file downloaded by scp may be installed setu ...