Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:47755

Опубликовано: 30 июл. 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: openssh security update

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.

Security Fix(es):

  • openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Rocky Linux OpenSSH client versions (CVE-2026-55655)

  • openssh: Double free in Rocky Linux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
opensshaarch6430.el8_10openssh-8.0p1-30.el8_10.aarch64.rpm
openssh-cavsaarch6430.el8_10openssh-cavs-8.0p1-30.el8_10.aarch64.rpm
openssh-clientsaarch6430.el8_10openssh-clients-8.0p1-30.el8_10.aarch64.rpm
openssh-keycataarch6430.el8_10openssh-keycat-8.0p1-30.el8_10.aarch64.rpm
openssh-ldapaarch6430.el8_10openssh-ldap-8.0p1-30.el8_10.aarch64.rpm
openssh-serveraarch6430.el8_10openssh-server-8.0p1-30.el8_10.aarch64.rpm
pam_ssh_agent_authaarch647.30.el8_10pam_ssh_agent_auth-0.10.3-7.30.el8_10.aarch64.rpm
opensshx86_6430.el8_10openssh-8.0p1-30.el8_10.x86_64.rpm
openssh-cavsx86_6430.el8_10openssh-cavs-8.0p1-30.el8_10.x86_64.rpm
openssh-clientsx86_6430.el8_10openssh-clients-8.0p1-30.el8_10.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
3 дня назад

ELSA-2026-47755: openssh security update (MODERATE)

rocky
3 дня назад

Important: openssh security update

rocky
3 дня назад

Important: openssh security update

oracle-oval
4 дня назад

ELSA-2026-47757: openssh security update (IMPORTANT)

CVSS3: 5
ubuntu
около 1 месяца назад

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.