Описание
ELSA-2026-50325: openssh security update (IMPORTANT)
[7.4p1-23.0.5_fips]
- Fix privilege escalation via scp legacy protocol when not in preserving file mode [CVE-2026-35385][Orabug: 39480251]
[7.4p1-23.0.3_fips]
- Change Epoch from 1 to 10
- Enable fips KDF POST [Orabug: 32461750]
- Disable diffie-hellman-group-exchange-sha256 KEX FIPS method [Orabug: 32461739]
Обновленные пакеты
Oracle Linux 7
Oracle Linux aarch64
openssh
7.4p1-23.0.5.el7_9_fips
openssh-askpass
7.4p1-23.0.5.el7_9_fips
openssh-cavs
7.4p1-23.0.5.el7_9_fips
openssh-clients
7.4p1-23.0.5.el7_9_fips
openssh-keycat
7.4p1-23.0.5.el7_9_fips
openssh-ldap
7.4p1-23.0.5.el7_9_fips
openssh-server
7.4p1-23.0.5.el7_9_fips
openssh-server-sysvinit
7.4p1-23.0.5.el7_9_fips
pam_ssh_agent_auth
0.10.3-2.23.0.5.el7_9_fips
Oracle Linux x86_64
openssh
7.4p1-23.0.5.el7_9_fips
openssh-askpass
7.4p1-23.0.5.el7_9_fips
openssh-cavs
7.4p1-23.0.5.el7_9_fips
openssh-clients
7.4p1-23.0.5.el7_9_fips
openssh-keycat
7.4p1-23.0.5.el7_9_fips
openssh-ldap
7.4p1-23.0.5.el7_9_fips
openssh-server
7.4p1-23.0.5.el7_9_fips
openssh-server-sysvinit
7.4p1-23.0.5.el7_9_fips
pam_ssh_agent_auth
0.10.3-2.23.0.5.el7_9_fips
Связанные CVE
Связанные уязвимости
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
In OpenSSH before 10.3, a file downloaded by scp may be installed setu ...