Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Mehrere Probleme in openssh (Red Hat)

Дата публикации: 30-07-2026 16:08:36



Основное содержимое страницы с новостью.

An update for openssh is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX,
and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.

Security Fix(es):

* openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in
Red Hat Enterprise Linux OpenSSH client versions (CVE-2026-55655)

* openssh: Double free in Red Hat Enterprise Linux versions of OpenSSH DH-GEX
client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653)

* openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of
OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination (CVE-2026-55654)

* openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on
the client side (CVE-2026-60002)

* openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy
(CVE-2026-59996)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2026-55653: Double Free (CWE-415)
CVE-2026-55654: Out-of-bounds Read (CWE-125)
CVE-2026-55655: Improper Restriction of Communication Channel to Intended
Endpoints (CWE-923)
CVE-2026-59996: Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal') (CWE-22)
CVE-2026-60002: Expired Pointer Dereference (CWE-825)

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Mehrere Probleme in openssh (Red Hat)01030-07-2026
2Zwei Probleme in openssh (Red Hat)01030-07-2026
3Mehrere Probleme in vim (Red Hat)01030-07-2026
4Mehrere Probleme in libssh (SUSE)01030-07-2026
5Mehrere Probleme in libssh (SUSE)01030-07-2026
6Mehrere Probleme in nodejs24 (Red Hat)01030-07-2026
7Zwei Probleme in python-pillow (Red Hat)026.6730-07-2026
8Mehrere Probleme in samba (SUSE)01030-07-2026
9Mehrere Probleme in nginx (SUSE)01030-07-2026
10Zwei Probleme in gstreamer1-plugins-bad-free (Red Hat)01030-07-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 10. Источник: www.pro-linux.de.