[Security Advisory] ALSA-2026:47756: openssh security update (Important)
Hi, You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux. AlmaLinux: 9 Type: Security Severity: Important Release date: 2026-07-31 Summary: OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server. Security Fix(es): * openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in AlmaLinux OpenSSH client versions (CVE-2026-55655) * openssh: Double free in AlmaLinux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653) * openssh: Heap out-of-bounds read in AlmaLinux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination (CVE-2026-55654) * openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side (CVE-2026-60002) * openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy (CVE-2026-59996) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-47756.html This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/. Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org. Kind regards, AlmaLinux Team
participants (1)
-
AlmaLinux Errata Notifications