[CLSA-2026:1784539708] openssh: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-20 09:28:52 UTC
Description:
- CVE-2026-60000: sshd did not subject GSSAPI authentication to MaxAuthTries and processed attacker-supplied error tokens pre-auth (DoS); discard the token in input_gssapi_errtok() and count the attempt via userauth_finish(). Backport upstream commit 5d04ca6d.
Updated packages:
  • openssh-8.0p1-24.el8.tuxcare.els9.x86_64.rpm
    sha:925c27bb2d38434aee8eba2d69d93a5146fad9320f21348d159eb05f13f634d5
  • openssh-askpass-8.0p1-24.el8.tuxcare.els9.x86_64.rpm
    sha:751701d0d531b17fe104b6097759a005dc27f2ae12a08b7d94668cb8755597e3
  • openssh-cavs-8.0p1-24.el8.tuxcare.els9.x86_64.rpm
    sha:e299a7c8640ac5f273b0ab6677fa969330a1081eaf2ce6b9d7b078158602159d
  • openssh-clients-8.0p1-24.el8.tuxcare.els9.x86_64.rpm
    sha:fb0187f38f1d6bdbd3fdeda4e5585741ef00ca45a2b06610fe035f6043418077
  • openssh-keycat-8.0p1-24.el8.tuxcare.els9.x86_64.rpm
    sha:75dcc478677c64f4e3e3a0b59ca2bf275e323668a7bdfeb4506b28617a9c667b
  • openssh-ldap-8.0p1-24.el8.tuxcare.els9.x86_64.rpm
    sha:b17d238a3ca958d19fe642891aec19bd0358653ec34589c5d61ab79e51cb750c
  • openssh-server-8.0p1-24.el8.tuxcare.els9.x86_64.rpm
    sha:8f66fe993b9e9eeddf4c1a24c4f3c9eff4ca4511e0ab283a64cae35398506f6f
  • pam_ssh_agent_auth-0.10.3-7.24.el8.tuxcare.els9.x86_64.rpm
    sha:9258bf2cf0f616c611aed8fa62013ff88991f29d2a38eaeab9f0615e46f0bccf
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.