Release date:
2026-08-26 15:06:36 UTC
Description:
* SECURITY UPDATE: use-after-free in the ssh client when a remote
forwarding is added over the multiplexing socket
- debian/patches/CVE-2026-73282.patch: pass a heap-allocated index
instead of a pointer into options.remote_forwards[] to
ssh_confirm_remote_forward() in ssh.c, so a concurrent
add_remote_forward() reallocation cannot leave the pending global
request confirmation holding a dangling pointer.
- CVE-2026-73282
* SECURITY UPDATE: authorized_keys restrict keyword did not cover
tunnel forwarding
- debian/patches/CVE-2026-73283.patch: also reject tunnel device
forwarding in server_request_tun() (serverloop.c) when the
authenticating key carries the restrict option.
- CVE-2026-73283
Updated packages:
-
openssh-client_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb
sha:f6534ff5482f5a04fdda3164f29852cec9c56ae0
-
openssh-server_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb
sha:dc2c9ef80e98725a733d4c74ed1337fb0741b093
-
openssh-sftp-server_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb
sha:d717c72d52c4d76a4058b02c7c779243cdff04d9
-
openssh-tests_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb
sha:8c11d2808626df41c4373de98206b2042501a77e
-
ssh_7.9p1-10+deb10u4+tuxcare.els7_all.deb
sha:ff56a495913908d57982e1c765299b6d03de9e75
-
ssh-askpass-gnome_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb
sha:00b588990eb1d177b74ba1be563a156d3b4bde86
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.