Release date:
2026-07-17 06:01:17 UTC
Description:
* SECURITY UPDATE: pre-authentication denial of service via GSSAPI
- debian/patches/CVE-2026-60000.patch: discard GSSAPI error tokens in
auth2-gss.c instead of feeding them into the GSSAPI stack, and count
the failed attempt so GSSAPI auth is subject to MaxAuthTries
- CVE-2026-60000
Updated packages:
-
openssh-client_7.6p1-4ubuntu0.7+tuxcare.els11_amd64.deb
sha:7d6c6d04008a45b0f2fea7a50588d2bdeda62267
-
openssh-server_7.6p1-4ubuntu0.7+tuxcare.els11_amd64.deb
sha:2c31307154cf724306264d4748847268f21a750e
-
openssh-sftp-server_7.6p1-4ubuntu0.7+tuxcare.els11_amd64.deb
sha:2f48881dd0d190b6af0efc75daefad96d160b45f
-
ssh_7.6p1-4ubuntu0.7+tuxcare.els11_all.deb
sha:5a30c4f4b48a130b963865ce3137c3fc1beb8257
-
ssh-askpass-gnome_7.6p1-4ubuntu0.7+tuxcare.els11_amd64.deb
sha:137a4fccc54e971676628f363b0515c3146d691c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.