Release date:
2026-07-21 12:15:21 UTC
Description:
- CVE-2026-60001: sshd did not enforce the minimum per-attempt authentication
delay in the GSSAPI and keyboard-interactive paths, enabling timing-based
user enumeration. Backport upstream commit d43ba60c.
Updated packages:
-
openssh-8.7p1-45.el9_6.tuxcare.els14.x86_64.rpm
sha:447a89be58309a755d8016f0887e20afd9d06e6a6350cc9ec8245ad5fdd05898
-
openssh-askpass-8.7p1-45.el9_6.tuxcare.els14.x86_64.rpm
sha:abc2935eeeddfd9692c1b80d8a6103dbdcdabc806b808b241459450920c10c4a
-
openssh-clients-8.7p1-45.el9_6.tuxcare.els14.x86_64.rpm
sha:cbe686fc732efd314aec02f8d2af1bc4c17fe6b5d566565cb1d98531ad565234
-
openssh-keycat-8.7p1-45.el9_6.tuxcare.els14.x86_64.rpm
sha:ed076147fd7c1ea933f5ebe647993fb0d829a909a552a32bb58874bfe6f42bc4
-
openssh-server-8.7p1-45.el9_6.tuxcare.els14.x86_64.rpm
sha:67c6fdac2d0bfa4fa16a7289b12d579534fce72891d3e7077f20f4b661d89ee0
-
openssh-sk-dummy-8.7p1-45.el9_6.tuxcare.els14.x86_64.rpm
sha:b4a0c14b6a955abc9a251a47c73548923d23f9e952749aca5dbe0734670aa5e4
-
pam_ssh_agent_auth-0.10.4-5.45.el9_6.tuxcare.els14.x86_64.rpm
sha:2809ef8dc969d8f3ba1782bad070aa32ba20692f93e20f605e5be35785246240
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.