Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-22468

Опубликовано: 18 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2026-22468: openssh security update (IMPORTANT)

[7.4p1-23.0.5]

  • Fix privilege escalation via scp legacy protocol when not in preserving file mode [CVE-2026-35385][Orabug: 39480251]

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

openssh

7.4p1-23.0.5.el7_9

openssh-askpass

7.4p1-23.0.5.el7_9

openssh-cavs

7.4p1-23.0.5.el7_9

openssh-clients

7.4p1-23.0.5.el7_9

openssh-keycat

7.4p1-23.0.5.el7_9

openssh-ldap

7.4p1-23.0.5.el7_9

openssh-server

7.4p1-23.0.5.el7_9

openssh-server-sysvinit

7.4p1-23.0.5.el7_9

pam_ssh_agent_auth

0.10.3-2.23.0.5.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

CVSS3: 7.5
redhat
4 месяца назад

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

CVSS3: 7.5
nvd
4 месяца назад

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

CVSS3: 7.5
msrc
4 месяца назад

Описание отсутствует

CVSS3: 7.5
debian
4 месяца назад

In OpenSSH before 10.3, a file downloaded by scp may be installed setu ...