[CLSA-2026:1787756777] Fix CVE(s): CVE-2026-73282, CVE-2026-73283
Type:
security
Severity:
Important
Release date:
2026-08-26 15:06:36 UTC
Description:
* SECURITY UPDATE: use-after-free in the ssh client when a remote forwarding is added over the multiplexing socket - debian/patches/CVE-2026-73282.patch: pass a heap-allocated index instead of a pointer into options.remote_forwards[] to ssh_confirm_remote_forward() in ssh.c, so a concurrent add_remote_forward() reallocation cannot leave the pending global request confirmation holding a dangling pointer. - CVE-2026-73282 * SECURITY UPDATE: authorized_keys restrict keyword did not cover tunnel forwarding - debian/patches/CVE-2026-73283.patch: also reject tunnel device forwarding in server_request_tun() (serverloop.c) when the authenticating key carries the restrict option. - CVE-2026-73283
Updated packages:
  • openssh-client_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb
    sha:f6534ff5482f5a04fdda3164f29852cec9c56ae0
  • openssh-server_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb
    sha:dc2c9ef80e98725a733d4c74ed1337fb0741b093
  • openssh-sftp-server_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb
    sha:d717c72d52c4d76a4058b02c7c779243cdff04d9
  • openssh-tests_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb
    sha:8c11d2808626df41c4373de98206b2042501a77e
  • ssh_7.9p1-10+deb10u4+tuxcare.els7_all.deb
    sha:ff56a495913908d57982e1c765299b6d03de9e75
  • ssh-askpass-gnome_7.9p1-10+deb10u4+tuxcare.els7_amd64.deb
    sha:00b588990eb1d177b74ba1be563a156d3b4bde86
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.