[CLSA-2026:1789380621] openssh: Fix of CVE-2026-73282
Type:
security
Severity:
Important
Release date:
2026-09-14 10:10:32 UTC
Description:
- CVE-2026-73282: avoid a potential realloc use-after-free in the ssh client when a remote forwarding is added via the local session multiplexing socket while a remote forwarding open request is pending, by passing a forwarding index instead of a raw options.remote_forwards pointer to ssh_confirm_remote_forward() (upstream 9910d5ef)
CVEs fixed:
Updated packages:
  • openssh-7.4p1-22.amzn2.0.13.tuxcare.els3.x86_64.rpm
    sha:f997d1715df8b4f35e53b23f79641adc23b5af99bafb64c38094559ff2ba0393
  • openssh-askpass-7.4p1-22.amzn2.0.13.tuxcare.els3.x86_64.rpm
    sha:fd219f323e26f00743cb7a38638b6a4c7b9766d566119344d7e9843c68037c41
  • openssh-cavs-7.4p1-22.amzn2.0.13.tuxcare.els3.x86_64.rpm
    sha:0fce539f6e2d1919bb771e584e5c91c7de0dc3bf1baab9fe48611e62a95915d9
  • openssh-clients-7.4p1-22.amzn2.0.13.tuxcare.els3.x86_64.rpm
    sha:ae62e66d8100f11343b087916c460fb28b68472422739ce9759681e37390bb90
  • openssh-keycat-7.4p1-22.amzn2.0.13.tuxcare.els3.x86_64.rpm
    sha:0a0e6270e86fccd290ccbc7be43dd7a12cafe936020133803fc60e290eb33f8e
  • openssh-ldap-7.4p1-22.amzn2.0.13.tuxcare.els3.x86_64.rpm
    sha:c90b811420748d066e081fca12395e1d23915e0b1bfa328d6fa4e1042c69a822
  • openssh-server-7.4p1-22.amzn2.0.13.tuxcare.els3.x86_64.rpm
    sha:ebd5bccbc93565d795ddd089ef971f1095504a49c293343039863928695ea4bc
  • openssh-server-sysvinit-7.4p1-22.amzn2.0.13.tuxcare.els3.x86_64.rpm
    sha:b66a719745fad8fede96608d5890b973e5884eeca01c2c7294655c4133c11c65
  • pam_ssh_agent_auth-0.10.3-2.22.amzn2.0.13.tuxcare.els3.x86_64.rpm
    sha:5708f8c9dad11fc50764bd3ff90429585d6e4ffdd358368372a7b51aaa46f35c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.