Описание
Security update for openssh, openssh-askpass-gnome
This update for openssh, openssh-askpass-gnome fixes the following issues
- CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427).
- CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430).
Список пакетов
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
openssh-6.6p1-36.31.1
openssh-askpass-gnome-6.6p1-36.31.1
openssh-cavs-6.6p1-36.31.1
openssh-fips-6.6p1-36.31.1
openssh-helpers-6.6p1-36.31.1
Ссылки
- Link for SUSE-SU-2026:2515-1
- E-Mail link for SUSE-SU-2026:2515-1
- SUSE Security Ratings
- SUSE Bug 1261427
- SUSE Bug 1261430
- SUSE Bug 1268421
- SUSE CVE CVE-2026-35385 page
- SUSE CVE CVE-2026-35414 page
Описание
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
Затронутые продукты
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-6.6p1-36.31.1
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-askpass-gnome-6.6p1-36.31.1
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-cavs-6.6p1-36.31.1
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-fips-6.6p1-36.31.1
Ссылки
- CVE-2026-35385
- SUSE Bug 1261427
- SUSE Bug 1267255
- SUSE Bug 1267879
Описание
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
Затронутые продукты
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-6.6p1-36.31.1
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-askpass-gnome-6.6p1-36.31.1
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-cavs-6.6p1-36.31.1
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE:openssh-fips-6.6p1-36.31.1
Ссылки
- CVE-2026-35414
- SUSE Bug 1261430
- SUSE Bug 1264198