Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-50325

Опубликовано: 25 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2026-50325: openssh security update (IMPORTANT)

[7.4p1-23.0.5_fips]

  • Fix privilege escalation via scp legacy protocol when not in preserving file mode [CVE-2026-35385][Orabug: 39480251]

[7.4p1-23.0.3_fips]

  • Change Epoch from 1 to 10
  • Enable fips KDF POST [Orabug: 32461750]
  • Disable diffie-hellman-group-exchange-sha256 KEX FIPS method [Orabug: 32461739]

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

openssh

7.4p1-23.0.5.el7_9_fips

openssh-askpass

7.4p1-23.0.5.el7_9_fips

openssh-cavs

7.4p1-23.0.5.el7_9_fips

openssh-clients

7.4p1-23.0.5.el7_9_fips

openssh-keycat

7.4p1-23.0.5.el7_9_fips

openssh-ldap

7.4p1-23.0.5.el7_9_fips

openssh-server

7.4p1-23.0.5.el7_9_fips

openssh-server-sysvinit

7.4p1-23.0.5.el7_9_fips

pam_ssh_agent_auth

0.10.3-2.23.0.5.el7_9_fips

Oracle Linux x86_64

openssh

7.4p1-23.0.5.el7_9_fips

openssh-askpass

7.4p1-23.0.5.el7_9_fips

openssh-cavs

7.4p1-23.0.5.el7_9_fips

openssh-clients

7.4p1-23.0.5.el7_9_fips

openssh-keycat

7.4p1-23.0.5.el7_9_fips

openssh-ldap

7.4p1-23.0.5.el7_9_fips

openssh-server

7.4p1-23.0.5.el7_9_fips

openssh-server-sysvinit

7.4p1-23.0.5.el7_9_fips

pam_ssh_agent_auth

0.10.3-2.23.0.5.el7_9_fips

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

CVSS3: 7.5
redhat
4 месяца назад

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

CVSS3: 7.5
nvd
4 месяца назад

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

CVSS3: 7.5
msrc
4 месяца назад

Описание отсутствует

CVSS3: 7.5
debian
4 месяца назад

In OpenSSH before 10.3, a file downloaded by scp may be installed setu ...