[CLSA-2026:1784899942] openssh: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-24 14:08:15 UTC
Description:
- CVE-2026-60000: sshd did not subject GSSAPI authentication to MaxAuthTries and processed attacker-supplied error tokens pre-auth (DoS); discard the token in input_gssapi_errtok() and count the attempt via userauth_finish(). Backport upstream commit 5d04ca6d.
Updated packages:
  • openssh-8.0p1-6.el8_4.2.tuxcare.els13.x86_64.rpm
    sha:0e23b1fb84f70192601e7b87358125e7072747aa9e7deb394bd5e89cfa76c945
  • openssh-askpass-8.0p1-6.el8_4.2.tuxcare.els13.x86_64.rpm
    sha:e14aba18a011eac428584f0dc198b9f98bb7aa7a1820e926eb3c2468c1dbf886
  • openssh-cavs-8.0p1-6.el8_4.2.tuxcare.els13.x86_64.rpm
    sha:44e7e1d27ce01ddc81685d13a7dae44b077a94d992aa58e7bdb828eca40e3eb1
  • openssh-clients-8.0p1-6.el8_4.2.tuxcare.els13.x86_64.rpm
    sha:c74f8a6e581d10c2c1330cd243ec0b76de81cab8976ef42c1a1aad845a659b7c
  • openssh-keycat-8.0p1-6.el8_4.2.tuxcare.els13.x86_64.rpm
    sha:01966ac795af4d79bf6304c32aeac68dc34b30abca30c41a669917a2e5d7725a
  • openssh-ldap-8.0p1-6.el8_4.2.tuxcare.els13.x86_64.rpm
    sha:b7d3798e85bbc9136f1f628b62719d238e28fc5513fdb2c91f04e47bab9745ff
  • openssh-server-8.0p1-6.el8_4.2.tuxcare.els13.x86_64.rpm
    sha:55a714f0810de0a4910b0476814a20178420e2625f1e1ad108783b03d8584c66
  • pam_ssh_agent_auth-0.10.3-7.6.el8_4.1.tuxcare.els13.x86_64.rpm
    sha:466afd1e325109004bed3312d5a9596a5786dabb5dbf4a0b0af9d4275b085015
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.