[CLSA-2026:1784846877] openssh: Fix of CVE-2026-60000
Type:
security
Severity:
Important
Release date:
2026-07-23 22:48:25 UTC
Description:
- CVE-2026-60000: fix GSSAPI pre-authentication denial of service where input_gssapi_errtok did not finish the postponed authentication attempt, so failed GSSAPI requests were never counted against MaxAuthTries
CVEs fixed:
Updated packages:
  • openssh-5.3p1-125.el6.tuxcare.els10.x86_64.rpm
    sha:d1df11a67e9b3f15c9168afddbb3fe5fa80e86bb6fd675b5b3bb07ff8ec9b12f
  • openssh-askpass-5.3p1-125.el6.tuxcare.els10.x86_64.rpm
    sha:f24e6520081bf70631d75fc5304240c40493f4e067c046a441d1b2c82db8fe98
  • openssh-clients-5.3p1-125.el6.tuxcare.els10.x86_64.rpm
    sha:a57f896fbd7aa949f2e56344f2292d43a2aa8ff32814066dc0465f65f229519d
  • openssh-ldap-5.3p1-125.el6.tuxcare.els10.x86_64.rpm
    sha:faa0f9e85ae0c06567ab09c42fce1ab442f84a152ca3c6b25bd2519a668a7ea0
  • openssh-server-5.3p1-125.el6.tuxcare.els10.x86_64.rpm
    sha:413cbbcd76e188bb87f09de0ee058088bbbf67988f94ceb3a07c2cb376127590
  • pam_ssh_agent_auth-0.9.3-125.el6.tuxcare.els10.i686.rpm
    sha:6e0bf61baf2138f9e8030a2d92a915e1787a4dd20c339b09c7a46c825cb40b34
  • pam_ssh_agent_auth-0.9.3-125.el6.tuxcare.els10.x86_64.rpm
    sha:3795be3c9fdd04846f671df8f42fa237ad91c9a34a48c386c10e77b8cba5e672
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.