openssh-8.0p1-30.el8_10
エラータID: AXSA:2026-1438:07
OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.
Security Fix(es):
* openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Asianux Server OpenSSH client versions (CVE-2026-55655)
* openssh: Double free in Asianux Server versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-55653
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
CVE-2026-55655
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
Update packages.
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
N/A
SRPMS
- openssh-8.0p1-30.el8_10.src.rpm
MD5: 7f8b463ab2104b305dc04e6c43ab9614
SHA-256: 3f0b796a35100c0f8cdb60aa657610d7ea609ca432dd77e8b321c31bfbd68015
Size: 2.90 MB
Asianux Server 8 for x86_64
- openssh-8.0p1-30.el8_10.x86_64.rpm
MD5: 3c64189195d17924be8e765ccc46adf9
SHA-256: ec2e6e5c0665897d3f9b7ed7a934a8c641d4fb87bcbb4a6026bceedec63e3bd7
Size: 527.35 kB - openssh-askpass-8.0p1-30.el8_10.x86_64.rpm
MD5: 453e62c337fdd050d408de711d105730
SHA-256: 1f4d13cb5ae369c3773d6efea5b6adcb739b1f5a13a0deb70fb959bb573ccd8c
Size: 96.05 kB - openssh-cavs-8.0p1-30.el8_10.x86_64.rpm
MD5: 574951582d00ab50ae50cab71b3a60c8
SHA-256: 8eda9ccb5ac0383a88e63612e0118f4e4b4f490580bd287041a1ebc368568623
Size: 234.61 kB - openssh-clients-8.0p1-30.el8_10.x86_64.rpm
MD5: ca92561a8fd65e20b44a3939b16b545f
SHA-256: 5f6110e550f91ae979027dd61868958d70492cb8471209d558dbda19742734cb
Size: 647.66 kB - openssh-keycat-8.0p1-30.el8_10.x86_64.rpm
MD5: 80a1099a589a0f0484e57394b6a86d41
SHA-256: 8f16e958bb81b4f5c6d279cdcf3d357a920af6c1910fcb4a187129c68bd7a097
Size: 119.41 kB - openssh-ldap-8.0p1-30.el8_10.x86_64.rpm
MD5: 08b073f0deb70e5c7fe5f05d26c7dbe4
SHA-256: 9b08fa831eb4f241c0cb78a5b50c8c401f5ca8e1db7d97a8e4567a517ea996a8
Size: 135.30 kB - openssh-server-8.0p1-30.el8_10.x86_64.rpm
MD5: 4bcec8e08de36ed08d9c945126de98f4
SHA-256: 38457abee02a5daa17fe271990f4df9cd3e4edcb0af8931fbd81ece5b6076a12
Size: 495.71 kB - pam_ssh_agent_auth-0.10.3-7.30.el8_10.x86_64.rpm
MD5: 874ffa8c19eea5cbacacb62b104e2648
SHA-256: f5103202411998e618e917a035a15cebd97a8e98caf4421c7861cb5e286095d6
Size: 210.93 kB