[CLSA-2026:1784846159] openssh: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-23 22:36:26 UTC
Description:
- CVE-2026-59999: make DisableForwarding=yes override PermitTunnel=yes in server_request_tun() (upstream 8dfe7ed6) - CVE-2026-60000: count postponed GSSAPI attempts against MaxAuthTries by finishing auth in input_gssapi_errtok(), fixing a pre-auth resource DoS (upstream 5d04ca6a)
Updated packages:
  • openssh-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:10e779b3efbb0ed20e7e3712fd7aae395be8bce06a3b0a2fe91e4da5edaff3ef
  • openssh-askpass-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:fb2b69c454897e892046e31aadcf6f95b4dc0cdc0c831f14991a8af1a0406203
  • openssh-cavs-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:135a4921c29a842f9b90a5d84677ca61f057ab9efceecba3fc75331ba435adc4
  • openssh-clients-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:836654a0dc79883320df2f7ffdc49247375bfa747d5c5801c69fa39607ba3916
  • openssh-keycat-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:10ad6e0cf77db07ef9993e4c83fa45de16ec0e2b39daa1e77d4789f7c43e214c
  • openssh-ldap-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:b38a24590152d8005708cb8cef89ea1db468447d337da6cf742414e5247cb17a
  • openssh-server-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:173aa10af5e42d63d19b0d6b1fa150e95fbae17e9f5873e9fb6474ae3ed414f6
  • openssh-server-sysvinit-7.4p1-23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:c49777cd04595e7ff5f6688344e2d3277fb3198d2ec7932d2483376a84264e2d
  • pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.tuxcare.els7.i686.rpm
    sha:a7b54153a20ffb0b956f6367eea601ed7cd702c09df41842c4337ff379449230
  • pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.tuxcare.els7.x86_64.rpm
    sha:fcc6779c75711787b6802918c40314774324eaf584551998742b8bfeb842c56d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.