[CLSA-2026:1789374596] Fix CVE(s): CVE-2026-59999, CVE-2026-60000, CVE-2026-73282
Type:
security
Severity:
Important
Release date:
2026-09-14 08:33:10 UTC
Description:
* SECURITY UPDATE: use-after-free in the ssh client when a remote forwarding is added over the multiplexing socket - debian/patches/CVE-2026-73282.patch: register a heap-allocated index instead of a pointer into options.remote_forwards[] as the pending remote-forward confirmation context in ssh.c, and re-resolve the array element in ssh_confirm_remote_forward(). - CVE-2026-73282
Updated packages:
  • openssh-client_8.4p1-5+deb11u7+tuxcare.els2_amd64.deb
    sha:1df05219ed07205929ca813151487b754f99fbe8
  • openssh-server_8.4p1-5+deb11u7+tuxcare.els2_amd64.deb
    sha:b5f1d08da3e21b52d5afed5771e1f6ee01296b36
  • openssh-sftp-server_8.4p1-5+deb11u7+tuxcare.els2_amd64.deb
    sha:c5a8072ef1146f07defbe034a86cb31c02ad2c99
  • openssh-tests_8.4p1-5+deb11u7+tuxcare.els2_amd64.deb
    sha:032e5433a18e1452c23b312398287ea96d5523a0
  • ssh_8.4p1-5+deb11u7+tuxcare.els2_all.deb
    sha:f4620d5fff2e1011c0de67ee545a22fb4f957b06
  • ssh-askpass-gnome_8.4p1-5+deb11u7+tuxcare.els2_amd64.deb
    sha:078d10a4efa5459809cdf95f4de1b99981ba73fb
  • openssh-client_8.4p1-5+deb11u7+tuxcare.els2_arm64.deb
    sha:924fb3a9bebc97ada02ca0f9700e991ca84694f0
  • openssh-server_8.4p1-5+deb11u7+tuxcare.els2_arm64.deb
    sha:7b042dba944b797104c45a504a173bf260a44046
  • openssh-sftp-server_8.4p1-5+deb11u7+tuxcare.els2_arm64.deb
    sha:e4a76b3249713f925763940a28a592506a8a2e30
  • openssh-tests_8.4p1-5+deb11u7+tuxcare.els2_arm64.deb
    sha:ee9f2af56e47de3e865ea55624a91f7dc4696819
  • ssh-askpass-gnome_8.4p1-5+deb11u7+tuxcare.els2_arm64.deb
    sha:b21c9ee348efef50dabc206126cc811ccada8c5b
  • openssh-client_8.4p1-5+deb11u7+tuxcare.els2_armel.deb
    sha:02f895be7359de3e7b47664a5872885c81455f55
  • openssh-server_8.4p1-5+deb11u7+tuxcare.els2_armel.deb
    sha:b37a92f16630300ecc14dce34e1429c1d7f18a80
  • openssh-sftp-server_8.4p1-5+deb11u7+tuxcare.els2_armel.deb
    sha:2cf5e5ad0c360b4c1f0fce93d2a60d3e2b9a3e1e
  • openssh-tests_8.4p1-5+deb11u7+tuxcare.els2_armel.deb
    sha:bd6b4b1f7547f6e094ae5215d970c9b8abc84770
  • ssh-askpass-gnome_8.4p1-5+deb11u7+tuxcare.els2_armel.deb
    sha:29432fb3f6f4f87614b9ef4657727ccab9aa897d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.