Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20757-1

Опубликовано: 15 мая 2026
Источник: suse-cvrf

Описание

Security update for openssh

This update for openssh fixes the following issues

Security issues fixed:

  • CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427).
  • CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430).

Other issues fixed:

  • SSH port not reachable on SLES-16.0-CHOST-BYOS since build 1.32 for both x86_64 and aarch64 (bsc#1262555).
  • OpenSSH audit support causes connection lost with parallel sessions (bsc#1252890).

Список пакетов

openSUSE Leap 16.0
openssh-10.0p2-160000.5.1
openssh-askpass-gnome-10.0p2-160000.5.1
openssh-cavs-10.0p2-160000.5.1
openssh-clients-10.0p2-160000.5.1
openssh-common-10.0p2-160000.5.1
openssh-helpers-10.0p2-160000.5.1
openssh-server-10.0p2-160000.5.1
openssh-server-config-rootlogin-10.0p2-160000.5.1

Описание

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).


Затронутые продукты
openSUSE Leap 16.0:openssh-10.0p2-160000.5.1
openSUSE Leap 16.0:openssh-askpass-gnome-10.0p2-160000.5.1
openSUSE Leap 16.0:openssh-cavs-10.0p2-160000.5.1
openSUSE Leap 16.0:openssh-clients-10.0p2-160000.5.1

Ссылки

Описание

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.


Затронутые продукты
openSUSE Leap 16.0:openssh-10.0p2-160000.5.1
openSUSE Leap 16.0:openssh-askpass-gnome-10.0p2-160000.5.1
openSUSE Leap 16.0:openssh-cavs-10.0p2-160000.5.1
openSUSE Leap 16.0:openssh-clients-10.0p2-160000.5.1

Ссылки