[CLSA-2026:1775220882] openssh: Fix of CVE-2026-3497
Type:
security
Severity:
Important
Release date:
2026-04-03 12:54:46 UTC
Description:
- CVE-2026-3497: terminate GSSAPI key exchange on protocol errors using ssh_packet_disconnect instead of sshpkt_disconnect (downstream gsskex patch)
Updated packages:
  • openssh-8.7p1-45.el9.tuxcare.els2.x86_64.rpm
    sha:54f6b5302eb52d174ab3b0faaa264a232b7bfde54a6d265ac251e5921348b156
  • openssh-askpass-8.7p1-45.el9.tuxcare.els2.x86_64.rpm
    sha:a87f1d2897e0970903f509743a3514f1bc06382f7a6d62d6ba9a489259002180
  • openssh-clients-8.7p1-45.el9.tuxcare.els2.x86_64.rpm
    sha:1ab7cfe9a82f4ce1f01d1ece4e534a1b739b2af4c2aca514f8675c3a9872ca92
  • openssh-keycat-8.7p1-45.el9.tuxcare.els2.x86_64.rpm
    sha:20c529e32b9cc29e2147a0de76ba5a8f9248c343e0cc8a6ab4c70515f3533f0e
  • openssh-server-8.7p1-45.el9.tuxcare.els2.x86_64.rpm
    sha:8a035b731354cef41366a0b6a4a0a93e7e3e486775f7de3557a3e8f53699ea41
  • openssh-sk-dummy-8.7p1-45.el9.tuxcare.els2.x86_64.rpm
    sha:0b9237fd6f57fba2d7369b0206c94e548b0359e2cfed6fa349af6627d0bd0122
  • pam_ssh_agent_auth-0.10.4-5.45.el9.tuxcare.els2.x86_64.rpm
    sha:fda5a023db10c508c3f56ffe1ee1ff14bfdb2621c6a76d818c405f5142dbe13e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.