Release date:
2026-07-22 16:06:59 UTC
Description:
* SECURITY UPDATE: pre-authentication denial of service via GSSAPI
- debian/patches/CVE-2026-60000.patch: discard GSSAPI error tokens in
auth2-gss.c instead of feeding them into the GSSAPI stack, and count
the failed attempt so GSSAPI auth is subject to MaxAuthTries.
- CVE-2026-60000
Updated packages:
-
openssh-client_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb
sha:3535ac92f49284eefebbd58e7d9328581f8c4247
-
openssh-server_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb
sha:23ac5f7838a7fa2814e9881ef5ea4af6c665a211
-
openssh-sftp-server_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb
sha:f40ea5b78d355de408c47ffb66f9ca0da0f737d9
-
openssh-tests_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb
sha:160e74019d57dbcaf81a177ed36a9a74ccc7f3ea
-
ssh_7.9p1-10+deb10u4+tuxcare.els6_all.deb
sha:3d6f541fcd03449d209cb8a0cb5f3078540452a9
-
ssh-askpass-gnome_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb
sha:56e71ef64be00e6c2eca0537cdca33736bb30980
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.