Описание
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.
A flaw was found in OpenSSH. This vulnerability allows a remote attacker to achieve arbitrary command execution by injecting shell metacharacters into a username provided on the command line. Exploitation requires an untrusted username and a non-default configuration of the '%' character in ssh_config.
Отчет
Red Hat products do not ship in a configuration which is subject to this vulnerability. Additionally, the impact of the command execution is limited to the scope of the specific user account which users would need to create themselves.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssh | Fix deferred | ||
| Red Hat Enterprise Linux 7 | openssh | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Enterprise Linux 10 | openssh | Fixed | RHSA-2026:13380 | 04.05.2026 |
| Red Hat Enterprise Linux 10 | openssh | Fixed | RHSA-2026:19069 | 19.05.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | openssh | Fixed | RHSA-2026:12389 | 30.04.2026 |
| Red Hat Enterprise Linux 8 | openssh | Fixed | RHSA-2026:13383 | 04.05.2026 |
| Red Hat Enterprise Linux 8 | openssh | Fixed | RHSA-2026:13383 | 04.05.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | openssh | Fixed | RHSA-2026:22329 | 01.06.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | openssh | Fixed | RHSA-2026:22329 | 01.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.6 Low
CVSS3
Связанные уязвимости
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.
In OpenSSH before 10.3, command execution can occur via shell metachar ...
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.
EPSS
3.6 Low
CVSS3