[CLSA-2026:1784268052] Fix CVE(s): CVE-2026-59999, CVE-2026-60000
Type:
security
Severity:
Important
Release date:
2026-07-17 06:01:17 UTC
Description:
* SECURITY UPDATE: pre-authentication denial of service via GSSAPI - debian/patches/CVE-2026-60000.patch: discard GSSAPI error tokens in auth2-gss.c instead of feeding them into the GSSAPI stack, and count the failed attempt so GSSAPI auth is subject to MaxAuthTries - CVE-2026-60000
Updated packages:
  • openssh-client_7.6p1-4ubuntu0.7+tuxcare.els11_amd64.deb
    sha:7d6c6d04008a45b0f2fea7a50588d2bdeda62267
  • openssh-server_7.6p1-4ubuntu0.7+tuxcare.els11_amd64.deb
    sha:2c31307154cf724306264d4748847268f21a750e
  • openssh-sftp-server_7.6p1-4ubuntu0.7+tuxcare.els11_amd64.deb
    sha:2f48881dd0d190b6af0efc75daefad96d160b45f
  • ssh_7.6p1-4ubuntu0.7+tuxcare.els11_all.deb
    sha:5a30c4f4b48a130b963865ce3137c3fc1beb8257
  • ssh-askpass-gnome_7.6p1-4ubuntu0.7+tuxcare.els11_amd64.deb
    sha:137a4fccc54e971676628f363b0515c3146d691c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.