[CLSA-2026:1784903674] Fix CVE(s): CVE-2026-60000
Type:
security
Severity:
Important
Release date:
2026-07-24 14:34:48 UTC
Description:
* SECURITY UPDATE: pre-authentication denial of service via GSSAPI - debian/patches/CVE-2026-60000.patch: discard GSSAPI error tokens in auth2-gss.c instead of feeding them into the GSSAPI stack, and count the failed attempt so GSSAPI auth is subject to MaxAuthTries - CVE-2026-60000
CVEs fixed:
Updated packages:
  • openssh-client_7.2p2-4ubuntu2.10+tuxcare.els10_amd64.deb
    sha:6ef9d17250731d52db8265856f8db06be4aaa57e
  • openssh-client-ssh1_7.2p2-4ubuntu2.10+tuxcare.els10_amd64.deb
    sha:db52aaab4cbea50e38b6bfbff9c27b0b92f32a42
  • openssh-server_7.2p2-4ubuntu2.10+tuxcare.els10_amd64.deb
    sha:04203f85eb678fe72de04cd4fc0f86ee6915bf92
  • openssh-sftp-server_7.2p2-4ubuntu2.10+tuxcare.els10_amd64.deb
    sha:158bb4a7f480327bf1ff2d80047081a5e4d9818b
  • ssh_7.2p2-4ubuntu2.10+tuxcare.els10_all.deb
    sha:18461aa500a0b3ee1e6111e1725878a2cd9759f8
  • ssh-askpass-gnome_7.2p2-4ubuntu2.10+tuxcare.els10_amd64.deb
    sha:55b1b59341be292fd4297c6a2148b289c25630a8
  • ssh-krb5_7.2p2-4ubuntu2.10+tuxcare.els10_all.deb
    sha:477f1b3e96f90886762f2d04cf973e1430c5cb23
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.