[CLSA-2026:1784725535] Fix CVE(s): CVE-2026-59999, CVE-2026-60000
Type:
security
Severity:
Important
Release date:
2026-07-22 13:06:03 UTC
Description:
* SECURITY UPDATE: DisableForwarding did not override PermitTunnel - debian/patches/CVE-2026-59999.patch: add options.disable_forwarding to the PermitTunnel gate in server_request_tun() in serverloop.c so that DisableForwarding=yes rejects tunnel-device forwarding as documented. - CVE-2026-59999 * SECURITY UPDATE: GSSAPI userauth pre-auth resource DoS / MaxAuthTries bypass - debian/patches/CVE-2026-60000.patch: discard the client error token in input_gssapi_errtok() instead of feeding it to ssh_gssapi_accept_ctx(), and record the failed attempt via userauth_finish() so GSSAPI auth is subject to MaxAuthTries, in auth2-gss.c. - CVE-2026-60000
Updated packages:
  • openssh-client_8.2p1-4ubuntu0.13+tuxcare.els4_amd64.deb
    sha:a5735d36267b60449d14f22823f0a2f47d5b160e
  • openssh-server_8.2p1-4ubuntu0.13+tuxcare.els4_amd64.deb
    sha:88b7adb96fbd3b7026ba0f4c4114e5ba111725a3
  • openssh-sftp-server_8.2p1-4ubuntu0.13+tuxcare.els4_amd64.deb
    sha:792448fe0a3deb7b2ecb4f3f3dcc4ffd14ab6d3a
  • openssh-tests_8.2p1-4ubuntu0.13+tuxcare.els4_amd64.deb
    sha:516507bbf1814b89a1faff34cf3717d7d31f1a0f
  • ssh_8.2p1-4ubuntu0.13+tuxcare.els4_all.deb
    sha:dd91826088b2b8072fdf8022b8d663aa2ad8530e
  • ssh-askpass-gnome_8.2p1-4ubuntu0.13+tuxcare.els4_amd64.deb
    sha:6be2bb3c3a8592badab4c2f1d60d1282c700b2df
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.