Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35388

Опубликовано: 02 апр. 2026
Источник: redhat
CVSS3: 2.2
EPSS Низкий

Описание

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

A flaw was found in OpenSSH. This vulnerability allows for a low integrity impact due to the omission of connection multiplexing confirmation for proxy-mode multiplexing sessions. A local user, under specific and complex conditions requiring user interaction, could potentially establish a multiplexed session without explicit confirmation, leading to unintended data handling.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6opensshFix deferred
Red Hat Enterprise Linux 7opensshFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10opensshFixedRHSA-2026:1338004.05.2026
Red Hat Enterprise Linux 10opensshFixedRHSA-2026:1906919.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportopensshFixedRHSA-2026:1238930.04.2026
Red Hat Enterprise Linux 8opensshFixedRHSA-2026:1338304.05.2026
Red Hat Enterprise Linux 8opensshFixedRHSA-2026:1338304.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportopensshFixedRHSA-2026:2232901.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnopensshFixedRHSA-2026:2232901.06.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=2454500OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions

EPSS

Процентиль: 3%
0.0013
Низкий

2.2 Low

CVSS3

Связанные уязвимости

CVSS3: 2.5
ubuntu
4 месяца назад

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

CVSS3: 2.5
nvd
4 месяца назад

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

CVSS3: 2.5
msrc
4 месяца назад

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

CVSS3: 2.5
debian
4 месяца назад

OpenSSH before 10.3 omits connection multiplexing confirmation for pro ...

CVSS3: 2.5
github
4 месяца назад

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

EPSS

Процентиль: 3%
0.0013
Низкий

2.2 Low

CVSS3