Описание
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
A flaw was found in OpenSSH. This vulnerability allows for a low integrity impact due to the omission of connection multiplexing confirmation for proxy-mode multiplexing sessions. A local user, under specific and complex conditions requiring user interaction, could potentially establish a multiplexed session without explicit confirmation, leading to unintended data handling.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssh | Fix deferred | ||
| Red Hat Enterprise Linux 7 | openssh | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred | ||
| Red Hat Enterprise Linux 10 | openssh | Fixed | RHSA-2026:13380 | 04.05.2026 |
| Red Hat Enterprise Linux 10 | openssh | Fixed | RHSA-2026:19069 | 19.05.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | openssh | Fixed | RHSA-2026:12389 | 30.04.2026 |
| Red Hat Enterprise Linux 8 | openssh | Fixed | RHSA-2026:13383 | 04.05.2026 |
| Red Hat Enterprise Linux 8 | openssh | Fixed | RHSA-2026:13383 | 04.05.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | openssh | Fixed | RHSA-2026:22329 | 01.06.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | openssh | Fixed | RHSA-2026:22329 | 01.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
2.2 Low
CVSS3
Связанные уязвимости
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
OpenSSH before 10.3 omits connection multiplexing confirmation for pro ...
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
EPSS
2.2 Low
CVSS3