[CLSA-2026:1777942153] openssh: Fix of CVE-2026-35385
Type:
security
Severity:
Important
Release date:
2026-05-07 16:59:34 UTC
Description:
- CVE-2026-35385: fix scp legacy protocol receiver to clear setuid/setgid bits from downloaded files when -p (preserve mode) is not set
Updated packages:
  • openssh-5.3p1-125.el6.tuxcare.els7.x86_64.rpm
    sha:4ea4663b75bb733176d4b4ca8dbb04603ab461f27ca544eec2d183300f3eb6ee
  • openssh-askpass-5.3p1-125.el6.tuxcare.els7.x86_64.rpm
    sha:03120cbccbf3432f79d7cdd187109d1bec78d9a2a4e257b593c525730209bd20
  • openssh-clients-5.3p1-125.el6.tuxcare.els7.x86_64.rpm
    sha:e7f666e0419b4cfb6ba1ada3a2eeb3205f81a08f30e99e64a13179b59f161833
  • openssh-ldap-5.3p1-125.el6.tuxcare.els7.x86_64.rpm
    sha:cb859cdeb02a49205204c853fcd8c416dc64c4222d4c1510a7a869874221a677
  • openssh-server-5.3p1-125.el6.tuxcare.els7.x86_64.rpm
    sha:b561919def51525484ce55cd873a871134ca989b0e95a133f1a4c9096787127b
  • pam_ssh_agent_auth-0.9.3-125.el6.tuxcare.els7.i686.rpm
    sha:44d78d6d2a93fe4841c08849b06f8ff8358155f5a7c1caaf33950c73a427ec36
  • pam_ssh_agent_auth-0.9.3-125.el6.tuxcare.els7.x86_64.rpm
    sha:e1e74d9e2d0c3aecf4a9e7a9e2c7d342f7630712162ea868c04039dab852d8af
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.