[CLSA-2026:1784736392] Fix CVE(s): CVE-2026-60000
Type:
security
Severity:
Important
Release date:
2026-07-22 16:06:59 UTC
Description:
* SECURITY UPDATE: pre-authentication denial of service via GSSAPI - debian/patches/CVE-2026-60000.patch: discard GSSAPI error tokens in auth2-gss.c instead of feeding them into the GSSAPI stack, and count the failed attempt so GSSAPI auth is subject to MaxAuthTries. - CVE-2026-60000
CVEs fixed:
Updated packages:
  • openssh-client_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb
    sha:3535ac92f49284eefebbd58e7d9328581f8c4247
  • openssh-server_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb
    sha:23ac5f7838a7fa2814e9881ef5ea4af6c665a211
  • openssh-sftp-server_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb
    sha:f40ea5b78d355de408c47ffb66f9ca0da0f737d9
  • openssh-tests_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb
    sha:160e74019d57dbcaf81a177ed36a9a74ccc7f3ea
  • ssh_7.9p1-10+deb10u4+tuxcare.els6_all.deb
    sha:3d6f541fcd03449d209cb8a0cb5f3078540452a9
  • ssh-askpass-gnome_7.9p1-10+deb10u4+tuxcare.els6_amd64.deb
    sha:56e71ef64be00e6c2eca0537cdca33736bb30980
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.