openssh-9.9p1-9.el9_8.ML.1
エラータID: AXSA:2026-1533:08
OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.
Security Fix(es):
* openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in MIRACLE LINUX OpenSSH client versions (CVE-2026-55655)
* openssh: Double free in MIRACLE LINUX versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653)
* openssh: Heap out-of-bounds read in MIRACLE LINUX versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination (CVE-2026-55654)
* openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side (CVE-2026-60002)
* openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy (CVE-2026-59996)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-55653
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
CVE-2026-55654
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
CVE-2026-55655
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
CVE-2026-59996
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
CVE-2026-60002
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Update packages.
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
N/A
SRPMS
- openssh-9.9p1-9.el9_8.ML.1.src.rpm
MD5: a6c0796b0f4b64936ab3168385c95b2c
SHA-256: a53b366b5b332c662f053dcf2840c751d462a7601cc8e4f891de0ba92a7badb2
Size: 2.43 MB
Asianux Server 9 for x86_64
- openssh-9.9p1-9.el9_8.ML.1.x86_64.rpm
MD5: f21e902bf4915d02e58235dc64d69afe
SHA-256: 1cad161932c0852640b1cb4b6e8bfca314493089a2c9d6ed9133fbcdb4d618e4
Size: 427.86 kB - openssh-askpass-9.9p1-9.el9_8.ML.1.x86_64.rpm
MD5: 936a3054069d1e8eafd453eab177cd07
SHA-256: 9ac09afc59362e0c4b6c2b55fe69e6e6ece2b7bd53b188c6038af2fed2efd737
Size: 17.93 kB - openssh-clients-9.9p1-9.el9_8.ML.1.x86_64.rpm
MD5: d8978dc029e7eae24215135eb0173157
SHA-256: e0ddf7522ddee62f58c6255786db4729fd67d7e785d2fe3269093129b8cba9a7
Size: 774.68 kB - openssh-keycat-9.9p1-9.el9_8.ML.1.x86_64.rpm
MD5: 04a53b31d7804352893ee6cff9dee805
SHA-256: 91bb280ee0be5ebd5d8b6206eef92c778dd336688ef7ca050eab7f2e549a533f
Size: 19.38 kB - openssh-server-9.9p1-9.el9_8.ML.1.x86_64.rpm
MD5: 3c8c4a4cc41e97710911e18daa1ec596
SHA-256: 65363bc2edfd1a4bafb9b15e57a6124ed386f1a43aa6ee82446d0435b24b7dc5
Size: 548.43 kB - pam_ssh_agent_auth-0.10.4-7.9.el9_8.ML.1.x86_64.rpm
MD5: 953d89d17534287d2d2bcf3403ab4944
SHA-256: 9502a4fefcbe4b888461aaeef6e7a2c0c80993281b58c74caa542842f40c902f
Size: 104.08 kB