Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59999

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

A flaw was found in sshd, the OpenSSH server daemon. When DisableForwarding=yes is configured to prevent network traffic forwarding, it incorrectly fails to take precedence over PermitTunnel=yes. This allows a remote attacker to bypass intended security restrictions and establish a tunnel, potentially leading to unauthorized network access or circumvention of security policies, even when forwarding is explicitly disabled.

Меры по смягчению последствий

To mitigate this issue, if DisableForwarding=yes is set in /etc/ssh/sshd_config to prevent all forwarding, ensure that PermitTunnel is explicitly set to no in the same configuration file. This will enforce the intended security policy. After modifying /etc/ssh/sshd_config, restart the sshd service for the changes to take effect. This may temporarily interrupt active SSH sessions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10opensshFix deferred
Red Hat Enterprise Linux 6opensshAffected
Red Hat Enterprise Linux 7opensshFix deferred
Red Hat Enterprise Linux 8opensshFix deferred
Red Hat Enterprise Linux 9opensshFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesopenssh-main-10.4p1-1.hum1FixedRHSA-2026:3738209.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=2497942openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options

EPSS

Процентиль: 6%
0.00159
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
25 дней назад

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

CVSS3: 5.9
nvd
25 дней назад

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

CVSS3: 5.9
msrc
24 дня назад

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

CVSS3: 5.9
debian
25 дней назад

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to ...

CVSS3: 5.9
github
25 дней назад

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

EPSS

Процентиль: 6%
0.00159
Низкий

5.9 Medium

CVSS3