[CLSA-2026:1784845335] openssh: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-24 09:54:14 UTC
Description:
- CVE-2026-59999: make DisableForwarding=yes override PermitTunnel=yes in server_request_tun() (upstream 8dfe7ed6) - CVE-2026-60000: count postponed GSSAPI attempts against MaxAuthTries by finishing auth in input_gssapi_errtok(), fixing a pre-auth resource DoS (upstream 5d04ca6a)
Updated packages:
  • openssh-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:906bbc4cee16a7bd5030fc64241a32c55901f82d6c28b85005ec6b351c1a01cf
  • openssh-askpass-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:bb17f922871b39892a7e5ac033555f7f590d3e6ad1b8f5ab7626857d3c79c90a
  • openssh-cavs-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:2edac1d04830cfe1e48951dda9815f65cce3f1c0a2bdaab78ce37a80d6ea4355
  • openssh-clients-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:4d56bc35fdccc6cad1253759b37c75f9fc44a87c78fa83604f8c2189d8dbba07
  • openssh-keycat-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:f8e26dc64be1e4033909c4f889d38a0fd18a072ca27bbaac243b96989526b2e9
  • openssh-ldap-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:f2a478cce56bb87a39e876ea281b005db24abb17e42bc9b71b3260f77146bbb7
  • openssh-server-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:4346ba3bc166a9235c99d584f7bc4716fdaf78514d694e583fbcbab0386a124b
  • openssh-server-sysvinit-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:0b736cd76fe39a42c201618c98b9f90070c90234756a4a701d2570293d5bc5c2
  • pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.tuxcare.els7.i686.rpm
    sha:7bfb5951237645f4641700141c1dec1dd2133028fb3519162a5576f8ad561e03
  • pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:6f604d54984ccfe97617565d70dcef89e820ed9eec11400e64bd631d54d0708c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.