Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3605-1

Опубликовано: 13 авг. 2026
Источник: suse-cvrf

Описание

Security update for openssh

This update for openssh fixes the following issues:

  • Backported support for the mlkemx25519 key exchange from upstream (jsc#PED-16473).

  • CVE-2026-59995: sftp: location of downloaded files not properly constrained when sftp server:/path . is used with an attacker-controlled server (bsc#1271044).

  • CVE-2026-59996: scp: file placed in the parent directory of an intended target directory when copy occurs between two remote destinations (bsc#1271046).

  • CVE-2026-59997: sshd: internal-sftp command lines are silently truncated after the 9th argument (bsc#1271048).

  • CVE-2026-59998: sshd: undocumented security-relevant GSSAPIStrictAcceptorCheck behavior in Windows Active Directory is not documented (bsc#1271049).

  • CVE-2026-59999: sshd: DisableForwarding=yes does not override PermitTunnel=yes (bsc#1271052).

  • CVE-2026-60000: sshd: pre-authentication denial of service when GSSAPIAuthentication is enabled (bsc#1271053).

  • CVE-2026-60001: sshd: minimum authentication delay is not honored (bsc#1271054).

  • CVE-2026-60002: ssh: client-side use-after-free when a server changes its host key during a key reexchange (bsc#1271055).

Список пакетов

Image SLES15-SP7-CHOST-BYOS-Aliyun
openssh-9.6p1-150600.6.49.1
openssh-clients-9.6p1-150600.6.49.1
openssh-common-9.6p1-150600.6.49.1
openssh-fips-9.6p1-150600.6.49.1
openssh-server-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-EC2
openssh-9.6p1-150600.6.49.1
openssh-clients-9.6p1-150600.6.49.1
openssh-common-9.6p1-150600.6.49.1
openssh-fips-9.6p1-150600.6.49.1
openssh-server-9.6p1-150600.6.49.1
openssh-server-config-disallow-rootlogin-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-GCE
openssh-9.6p1-150600.6.49.1
openssh-clients-9.6p1-150600.6.49.1
openssh-common-9.6p1-150600.6.49.1
openssh-fips-9.6p1-150600.6.49.1
openssh-server-9.6p1-150600.6.49.1
openssh-server-config-disallow-rootlogin-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-GDC
openssh-9.6p1-150600.6.49.1
openssh-clients-9.6p1-150600.6.49.1
openssh-common-9.6p1-150600.6.49.1
openssh-fips-9.6p1-150600.6.49.1
openssh-server-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-SAP-CCloud
openssh-9.6p1-150600.6.49.1
openssh-clients-9.6p1-150600.6.49.1
openssh-common-9.6p1-150600.6.49.1
openssh-fips-9.6p1-150600.6.49.1
openssh-server-9.6p1-150600.6.49.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
openssh-9.6p1-150600.6.49.1
openssh-clients-9.6p1-150600.6.49.1
openssh-common-9.6p1-150600.6.49.1
openssh-fips-9.6p1-150600.6.49.1
openssh-helpers-9.6p1-150600.6.49.1
openssh-server-9.6p1-150600.6.49.1
openssh-server-config-disallow-rootlogin-9.6p1-150600.6.49.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP7
openssh-askpass-gnome-9.6p1-150600.6.49.1
SUSE Linux Enterprise Server 15 SP6-LTSS
openssh-9.6p1-150600.6.49.1
openssh-askpass-gnome-9.6p1-150600.6.49.1
openssh-clients-9.6p1-150600.6.49.1
openssh-common-9.6p1-150600.6.49.1
openssh-fips-9.6p1-150600.6.49.1
openssh-helpers-9.6p1-150600.6.49.1
openssh-server-9.6p1-150600.6.49.1
openssh-server-config-disallow-rootlogin-9.6p1-150600.6.49.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
openssh-9.6p1-150600.6.49.1
openssh-askpass-gnome-9.6p1-150600.6.49.1
openssh-clients-9.6p1-150600.6.49.1
openssh-common-9.6p1-150600.6.49.1
openssh-fips-9.6p1-150600.6.49.1
openssh-helpers-9.6p1-150600.6.49.1
openssh-server-9.6p1-150600.6.49.1
openssh-server-config-disallow-rootlogin-9.6p1-150600.6.49.1

Описание

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.


Затронутые продукты
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-clients-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-common-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-fips-9.6p1-150600.6.49.1

Ссылки

Описание

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.


Затронутые продукты
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-clients-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-common-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-fips-9.6p1-150600.6.49.1

Ссылки

Описание

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.


Затронутые продукты
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-clients-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-common-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-fips-9.6p1-150600.6.49.1

Ссылки

Описание

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.


Затронутые продукты
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-clients-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-common-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-fips-9.6p1-150600.6.49.1

Ссылки

Описание

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.


Затронутые продукты
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-clients-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-common-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-fips-9.6p1-150600.6.49.1

Ссылки

Описание

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.


Затронутые продукты
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-clients-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-common-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-fips-9.6p1-150600.6.49.1

Ссылки

Описание

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.


Затронутые продукты
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-clients-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-common-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-fips-9.6p1-150600.6.49.1

Ссылки

Описание

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)


Затронутые продукты
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-clients-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-common-9.6p1-150600.6.49.1
Image SLES15-SP7-CHOST-BYOS-Aliyun:openssh-fips-9.6p1-150600.6.49.1

Ссылки