Release date:
2026-07-16 12:22:11 UTC
Description:
- CVE-2026-60000: sshd did not subject GSSAPI authentication to MaxAuthTries and
processed attacker-supplied error tokens pre-auth (DoS); discard the token in
input_gssapi_errtok() and count the attempt via userauth_finish(). Backport
upstream commit 5d04ca6d.
Updated packages:
-
openssh-8.0p1-10.el8.tuxcare.els13.x86_64.rpm
sha:170453d252942734c95d7aa445233d665bcec32e5c16f32e0e1f5c33fa19ddde
-
openssh-askpass-8.0p1-10.el8.tuxcare.els13.x86_64.rpm
sha:40d68e2166b90ddba8d48619428d79126b6d76e35d49da46e4586c479145ff14
-
openssh-cavs-8.0p1-10.el8.tuxcare.els13.x86_64.rpm
sha:ee283fce18a29549e0ee03a6ae38a5c9afd615fb44a6b91dab40db9608d74785
-
openssh-clients-8.0p1-10.el8.tuxcare.els13.x86_64.rpm
sha:7a547de23f901d78c193b91a1b78a80ebc9ecae88ee1bf9dc9219c35986630c8
-
openssh-keycat-8.0p1-10.el8.tuxcare.els13.x86_64.rpm
sha:1d2a88c018ceb57d324d349197808e26ea49ef7aa1a410a25ba7c4a26139ca62
-
openssh-ldap-8.0p1-10.el8.tuxcare.els13.x86_64.rpm
sha:57b883b1ac5e12418e3db7eab17dbbcde1be036e0de0ca9dc8df01c16eadd75a
-
openssh-server-8.0p1-10.el8.tuxcare.els13.x86_64.rpm
sha:dcd179ed1c25e29b21690c57a22cf976fce406bfca19591a4e41947161fde9c8
-
pam_ssh_agent_auth-0.10.3-7.10.el8.tuxcare.els13.x86_64.rpm
sha:3cbcaea6b845deb6f203f0f839bd4ed0cbb739fe1a81716662e7ac3ca9a73bf3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.