Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2515-1

Опубликовано: 23 июн. 2026
Источник: suse-cvrf

Описание

Security update for openssh, openssh-askpass-gnome

This update for openssh, openssh-askpass-gnome fixes the following issues

  • CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427).
  • CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430).

Список пакетов

SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
openssh-6.6p1-36.31.1
openssh-askpass-gnome-6.6p1-36.31.1
openssh-cavs-6.6p1-36.31.1
openssh-fips-6.6p1-36.31.1
openssh-helpers-6.6p1-36.31.1

Описание

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-6.6p1-36.31.1
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-askpass-gnome-6.6p1-36.31.1
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-cavs-6.6p1-36.31.1
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-fips-6.6p1-36.31.1

Ссылки

Описание

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.


Затронутые продукты
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-6.6p1-36.31.1
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-askpass-gnome-6.6p1-36.31.1
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-cavs-6.6p1-36.31.1
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-fips-6.6p1-36.31.1

Ссылки