[CLSA-2026:1778233384] openssh: Fix of CVE-2026-35386
Type:
security
Severity:
Important
Release date:
2026-05-13 08:58:53 UTC
Description:
- CVE-2026-35386: fix client-side command execution via control characters in usernames by adding iscntrl rejection to valid_ruser
Updated packages:
  • openssh-5.3p1-125.el6.tuxcare.els9.x86_64.rpm
    sha:8813bfd86749727c8b181283d88526b2edb1cd71b5099a613282ad753d1753c5
  • openssh-askpass-5.3p1-125.el6.tuxcare.els9.x86_64.rpm
    sha:31129d6e82a15bc22579e863fc9fdf092509850b59019ad2264c23cd5dd5490d
  • openssh-clients-5.3p1-125.el6.tuxcare.els9.x86_64.rpm
    sha:42164f4ecba809467ae87de789dc59f11852ee90b439eb193b816bd254024208
  • openssh-ldap-5.3p1-125.el6.tuxcare.els9.x86_64.rpm
    sha:9e3f6b63b7848689c568c619e2eecc717eb49f5601403e844de12bb3d117cb1c
  • openssh-server-5.3p1-125.el6.tuxcare.els9.x86_64.rpm
    sha:6ed03c313846ce8078eb1f6ac4be1708e76cbd3a075b6074df3afbbcc4d207fd
  • pam_ssh_agent_auth-0.9.3-125.el6.tuxcare.els9.i686.rpm
    sha:d3bffdc58a98a0d917f16cd44a4344145b7c3846eaf522f0ba7d913d5a11a759
  • pam_ssh_agent_auth-0.9.3-125.el6.tuxcare.els9.x86_64.rpm
    sha:fff50908e4d1911d081dd8db6771a9a282713c5db296b1d289ee25f3606dc16b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.