openssh-9.9p1-11.el9_8.ML.1

エラータID: AXSA:2026-1891:11

リリース日: 
2026/09/23 Wednesday - 22:47
題名: 
openssh-9.9p1-11.el9_8.ML.1
影響のあるチャネル: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.

Security Fix(es):

* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)
* openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)
* openssh: OpenSSH: Tunnel forwarding restriction bypass (CVE-2026-73283)
* openssh: OpenSSH: ssh-agent allows remote execution of local operations (CVE-2026-73281)
* openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-59995
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
CVE-2026-59999
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CVE-2026-73281
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
CVE-2026-73282
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CVE-2026-73283
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. openssh-9.9p1-11.el9_8.ML.1.src.rpm
    MD5: a1a84089ae726c6597412ffc58e50bfe
    SHA-256: e677a49d1954626bef61a9e8dd6725c6a9ed954e68669e6010f80bfe1bdd4c04
    Size: 2.44 MB

Asianux Server 9 for x86_64
  1. openssh-9.9p1-11.el9_8.ML.1.x86_64.rpm
    MD5: 558af72c7dc75f96326da0b7fc051498
    SHA-256: 3dce12ba5ea4327e48a34dfa9b710da657593a6d410f3c1c4f3901da35f87e35
    Size: 428.60 kB
  2. openssh-askpass-9.9p1-11.el9_8.ML.1.x86_64.rpm
    MD5: 8a3c6a060888b3bbaf68e59a4c0b87b6
    SHA-256: 1008db758f6919803cc8d944944f88a8a601eb13a358b40d1a700e56c7ff4c69
    Size: 18.70 kB
  3. openssh-clients-9.9p1-11.el9_8.ML.1.x86_64.rpm
    MD5: fdb0f9e52a0309d197a8ac379cc2f119
    SHA-256: b825cbc7e72ada276bb0876d77e4019692e27bc6ff8172e006de18850dc307f0
    Size: 775.48 kB
  4. openssh-keycat-9.9p1-11.el9_8.ML.1.x86_64.rpm
    MD5: bfb62e0c5b81cef9bfcb34e4f35f2e80
    SHA-256: 7f02e6fe6b72f47fe8c0a67c4bee8465b71ca97aa321c516903c0dae328914ab
    Size: 20.14 kB
  5. openssh-server-9.9p1-11.el9_8.ML.1.x86_64.rpm
    MD5: 32136e4738373397eb7259655f4f0fce
    SHA-256: 7678fb0c3dfa18386ef6f1573d1dbaaef31e5a6f17ffe0a1045799a044b454de
    Size: 549.45 kB
  6. pam_ssh_agent_auth-0.10.4-8.11.el9_8.ML.1.x86_64.rpm
    MD5: 4e90e5ef7684219cb60c1e54749da95d
    SHA-256: d3fe42ffaa944b7634b9020d57f2a5cfb129612c7fb437010d8f1e1185b937a1
    Size: 104.83 kB