Описание
Security update for openssh
This update for openssh fixes the following issues:
-
Backported support for the mlkemx25519 key exchange from upstream (jsc#PED-16473).
-
CVE-2026-59995: sftp: location of downloaded files not properly constrained when
sftp server:/path .is used with an attacker-controlled server (bsc#1271044). -
CVE-2026-59996: scp: file placed in the parent directory of an intended target directory when copy occurs between two remote destinations (bsc#1271046).
-
CVE-2026-59997: sshd:
internal-sftpcommand lines are silently truncated after the 9th argument (bsc#1271048). -
CVE-2026-59998: sshd: undocumented security-relevant
GSSAPIStrictAcceptorCheckbehavior in Windows Active Directory is not documented (bsc#1271049). -
CVE-2026-59999: sshd:
DisableForwarding=yesdoes not overridePermitTunnel=yes(bsc#1271052). -
CVE-2026-60000: sshd: pre-authentication denial of service when GSSAPIAuthentication is enabled (bsc#1271053).
-
CVE-2026-60001: sshd: minimum authentication delay is not honored (bsc#1271054).
-
CVE-2026-60002: ssh: client-side use-after-free when a server changes its host key during a key reexchange (bsc#1271055).
Список пакетов
Image SLES15-SP7-CHOST-BYOS-Aliyun
Image SLES15-SP7-CHOST-BYOS-EC2
Image SLES15-SP7-CHOST-BYOS-GCE
Image SLES15-SP7-CHOST-BYOS-GDC
Image SLES15-SP7-CHOST-BYOS-SAP-CCloud
SUSE Linux Enterprise Module for Basesystem 15 SP7
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
SUSE Linux Enterprise Server 15 SP6-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP6
Ссылки
- Link for SUSE-SU-2026:3605-1
- E-Mail link for SUSE-SU-2026:3605-1
- SUSE Security Ratings
- SUSE Bug 1271044
- SUSE Bug 1271046
- SUSE Bug 1271048
- SUSE Bug 1271049
- SUSE Bug 1271052
- SUSE Bug 1271053
- SUSE Bug 1271054
- SUSE Bug 1271055
- SUSE CVE CVE-2026-59995 page
- SUSE CVE CVE-2026-59996 page
- SUSE CVE CVE-2026-59997 page
- SUSE CVE CVE-2026-59998 page
- SUSE CVE CVE-2026-59999 page
- SUSE CVE CVE-2026-60000 page
- SUSE CVE CVE-2026-60001 page
- SUSE CVE CVE-2026-60002 page
Описание
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
Затронутые продукты
Ссылки
- CVE-2026-59995
- SUSE Bug 1271044
Описание
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
Затронутые продукты
Ссылки
- CVE-2026-59996
- SUSE Bug 1271046
Описание
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
Затронутые продукты
Ссылки
- CVE-2026-59997
- SUSE Bug 1271048
Описание
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
Затронутые продукты
Ссылки
- CVE-2026-59998
- SUSE Bug 1271049
Описание
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
Затронутые продукты
Ссылки
- CVE-2026-59999
- SUSE Bug 1271052
Описание
sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.
Затронутые продукты
Ссылки
- CVE-2026-60000
- SUSE Bug 1271053
Описание
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
Затронутые продукты
Ссылки
- CVE-2026-60001
- SUSE Bug 1271054
Описание
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Затронутые продукты
Ссылки
- CVE-2026-60002
- SUSE Bug 1271055
- SUSE Bug 1271636
- SUSE Bug 1271706