[CLSA-2026:1784634529] openssh: Fix of CVE-2026-60001
Type:
security
Severity:
Moderate
Release date:
2026-07-21 11:49:15 UTC
Description:
- CVE-2026-60001: sshd did not enforce the minimum per-attempt authentication delay in the GSSAPI and keyboard-interactive paths, enabling timing-based user enumeration. Backport upstream commit d43ba60c.
CVEs fixed:
Updated packages:
  • openssh-8.7p1-30.el9_2.tuxcare.els21.x86_64.rpm
    sha:be6381b93b60b443eb9b3dfd9f7ad9caa551298890519631f03ec2e32d825a65
  • openssh-askpass-8.7p1-30.el9_2.tuxcare.els21.x86_64.rpm
    sha:78a970c5de745991984e905c7a4cbc83cb1dd345812d9d15d3fa07a9996216c2
  • openssh-clients-8.7p1-30.el9_2.tuxcare.els21.x86_64.rpm
    sha:f85480382a031a26ac2c6848c5859084ca6f029e67ed82ed9a6c2654373e3abb
  • openssh-keycat-8.7p1-30.el9_2.tuxcare.els21.x86_64.rpm
    sha:634ac96a6b42e035662f56cd50dc20eab287b6f430bb9fd3c95bee9514bb2995
  • openssh-server-8.7p1-30.el9_2.tuxcare.els21.x86_64.rpm
    sha:4e33199a9435c6064298803c93f032927e0141832aced56f7adc6fcc8deaaede
  • openssh-sk-dummy-8.7p1-30.el9_2.tuxcare.els21.x86_64.rpm
    sha:9b38187a478719bb4a14ab44d3fe0b26a7f8538443c635a05b32417a1f7eb53f
  • pam_ssh_agent_auth-0.10.4-5.30.el9_2.tuxcare.els21.x86_64.rpm
    sha:90e88c7155f1fb725f7baf63d1e73d315372b8c1363c4106606f72e42bd6c8d9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.