[CLSA-2026:1767627264] openssh: Fix of CVE-2025-61985
Type:
security
Severity:
Moderate
Release date:
2026-01-05 15:34:28 UTC
Description:
- CVE-2025-61985: potential code execution using the ‘\0’ character in an ssh:// URI, when a ProxyCommand is used
Updated packages:
  • openssh-8.0p1-10.el8.tuxcare.els8.x86_64.rpm
    sha:f06f708caaee196c906f5f4946db2923c4e643b2ff2a3a64505dac542ebd46c3
  • openssh-askpass-8.0p1-10.el8.tuxcare.els8.x86_64.rpm
    sha:cfafff485a0b67092972b48b09da343f693ffe098cce39642a1f3f4a95cd7d2c
  • openssh-cavs-8.0p1-10.el8.tuxcare.els8.x86_64.rpm
    sha:04b73fa0247e07138069e07a68e41862b7526dbc44450b4328e17b5bc21c5485
  • openssh-clients-8.0p1-10.el8.tuxcare.els8.x86_64.rpm
    sha:edfe4bc01ef0a9320d98ff5fc64efc860db5db9d9fc4663d8d51464bf49f055e
  • openssh-keycat-8.0p1-10.el8.tuxcare.els8.x86_64.rpm
    sha:9b65e46dc49c8fae5e8cca2e735fd372e32bc0ecc30ac888a1a129e1f89c6b80
  • openssh-ldap-8.0p1-10.el8.tuxcare.els8.x86_64.rpm
    sha:8d6f91297ee47675e53ddf88e0bf1a64ee41e0c3a0d9824438b174aeb321973f
  • openssh-server-8.0p1-10.el8.tuxcare.els8.x86_64.rpm
    sha:de74a7dae41bf7934df4bc6664ed17a2e0d516e12052edf6cc040da47ce73a62
  • pam_ssh_agent_auth-0.10.3-7.10.el8.tuxcare.els8.x86_64.rpm
    sha:113aff6163ddd1c5779f618a216493128f080709856f1d94641b3b545e28447c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.