Release date:
2026-07-22 13:06:03 UTC
Description:
* SECURITY UPDATE: DisableForwarding did not override PermitTunnel
- debian/patches/CVE-2026-59999.patch: add options.disable_forwarding to
the PermitTunnel gate in server_request_tun() in serverloop.c so that
DisableForwarding=yes rejects tunnel-device forwarding as documented.
- CVE-2026-59999
* SECURITY UPDATE: GSSAPI userauth pre-auth resource DoS / MaxAuthTries bypass
- debian/patches/CVE-2026-60000.patch: discard the client error token in
input_gssapi_errtok() instead of feeding it to ssh_gssapi_accept_ctx(),
and record the failed attempt via userauth_finish() so GSSAPI auth is
subject to MaxAuthTries, in auth2-gss.c.
- CVE-2026-60000
Updated packages:
-
openssh-client_8.2p1-4ubuntu0.13+tuxcare.els4_amd64.deb
sha:a5735d36267b60449d14f22823f0a2f47d5b160e
-
openssh-server_8.2p1-4ubuntu0.13+tuxcare.els4_amd64.deb
sha:88b7adb96fbd3b7026ba0f4c4114e5ba111725a3
-
openssh-sftp-server_8.2p1-4ubuntu0.13+tuxcare.els4_amd64.deb
sha:792448fe0a3deb7b2ecb4f3f3dcc4ffd14ab6d3a
-
openssh-tests_8.2p1-4ubuntu0.13+tuxcare.els4_amd64.deb
sha:516507bbf1814b89a1faff34cf3717d7d31f1a0f
-
ssh_8.2p1-4ubuntu0.13+tuxcare.els4_all.deb
sha:dd91826088b2b8072fdf8022b8d663aa2ad8530e
-
ssh-askpass-gnome_8.2p1-4ubuntu0.13+tuxcare.els4_amd64.deb
sha:6be2bb3c3a8592badab4c2f1d60d1282c700b2df
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.