openssh-8.0p1-33.el8_10
エラータID: AXSA:2026-1886:10
OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.
Security Fix(es):
* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)
* openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)
* openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)
Bug Fix(es) and Enhancement(s):
* Incomplete backport of CVE-2023-38408 in RHEL 8 openssh (JIRA:RHEL-234763)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2023-38408
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
CVE-2026-59995
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
CVE-2026-59999
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CVE-2026-73282
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
Update packages.
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
N/A
SRPMS
- openssh-8.0p1-33.el8_10.src.rpm
MD5: 9fd00b640000bd96788dff1a4f48ad76
SHA-256: f6521e68722808ee19092b3ec5347f34c8eeb8a1ccb20a8c15c148723baa0db6
Size: 2.90 MB
Asianux Server 8 for x86_64
- openssh-8.0p1-33.el8_10.x86_64.rpm
MD5: 0619354477c7cf1151689027e4f6aa02
SHA-256: 547a39b271d5fc7b41e6f3707cd588b6edefbd8827d34838dc73e080621a77ed
Size: 502.84 kB - openssh-askpass-8.0p1-33.el8_10.x86_64.rpm
MD5: 9c9ef7b941edf9ea814f4e270099f5fb
SHA-256: 11559753dab3be0ce995ef30acf3950aaeb6ff148862467101c848245b42627f
Size: 96.65 kB - openssh-cavs-8.0p1-33.el8_10.x86_64.rpm
MD5: 5fd9c2b58aaadc5fa0f0e1d3f176d49d
SHA-256: 79feafe679fdb0797bd5c8cd1ea76b967cbac27ab29e7c93c632d7cd500b7250
Size: 235.70 kB - openssh-clients-8.0p1-33.el8_10.x86_64.rpm
MD5: a6bee43b3c33d78e6fc4310dd9e7f12d
SHA-256: 1f38f816497089ceb57e0f19f152b3e219cb5a297e7ee0da3562043bf05d043f
Size: 700.64 kB - openssh-keycat-8.0p1-33.el8_10.x86_64.rpm
MD5: 470bd1728045ba2e6269946e8c937ca8
SHA-256: a180bb812738dbf907dc18be8830b2e3ea14f71b1859270630c05e34faa758fd
Size: 120.46 kB - openssh-ldap-8.0p1-33.el8_10.x86_64.rpm
MD5: 244523a9aa8f51ded055b8f049bc3d1d
SHA-256: d832f8cf848028043cfb85f95f7cbd0238a15300a89895cdddfdcb566b06e340
Size: 136.30 kB - openssh-server-8.0p1-33.el8_10.x86_64.rpm
MD5: 6d289a58e1b3a78ae8c8388489052d86
SHA-256: d657f62e2557f4440a0ee8bda19e8e1ea09457af24a5ea0bfe77efa58e184019
Size: 497.01 kB - pam_ssh_agent_auth-0.10.3-8.33.el8_10.x86_64.rpm
MD5: 838fb495f5f1c7f08b58de0c9eebc4c1
SHA-256: 1429bb5a98753f6a1a45b885cb4eaa58afdabb38e55bf897c7cc0d89d31ee846
Size: 211.92 kB