Описание
ELSA-2026-47757: openssh security update (IMPORTANT)
[9.9p1-25.0.1]
- Upstream references found with /usr/bin/ssh [Orabug: 37824421]
[9.9p1-25]
- CVE-2026-59996: Fix remote glob result of '..' causing files to be placed in unintended parent directories when scp performs remote-to-remote copy via the local host Resolves: RHEL-193170
- CVE-2026-60002: Fix use-after-free in cached hostkey during key re-exchange Resolves: RHEL-193016
[9.9p1-24]
- CVE-2026-55653: Fix double free in openssh DH-GEX client path during FIPS known-group validation that leads to client-side denial of service Resolves: RHEL-186435
- CVE-2026-55654: Fix heap out-of-bounds read during GSSAPI indicator cleanup due to missing NULL terminator Resolves: RHEL-185826
- CVE-2026-55655: Fix MITM of X11 forwarding via abstract UNIX socket pre-binding Resolves: RHEL-185852
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
openssh
9.9p1-25.0.1.el10_2
openssh-askpass
9.9p1-25.0.1.el10_2
openssh-clients
9.9p1-25.0.1.el10_2
openssh-keycat
9.9p1-25.0.1.el10_2
openssh-keysign
9.9p1-25.0.1.el10_2
openssh-server
9.9p1-25.0.1.el10_2
Oracle Linux x86_64
openssh
9.9p1-25.0.1.el10_2
openssh-askpass
9.9p1-25.0.1.el10_2
openssh-clients
9.9p1-25.0.1.el10_2
openssh-keycat
9.9p1-25.0.1.el10_2
openssh-keysign
9.9p1-25.0.1.el10_2
openssh-server
9.9p1-25.0.1.el10_2
Ссылки на источники
Связанные уязвимости
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).