[CLSA-2026:1777453856] openssh: Fix of CVE-2026-35414
Type:
security
Severity:
Important
Release date:
2026-04-29 09:11:01 UTC
Description:
- CVE-2026-35414: fix incorrect matching of principals in the authorized_keys principals="..." option when a certificate principal contains a comma character
Updated packages:
  • openssh-8.0p1-10.el8.tuxcare.els10.x86_64.rpm
    sha:c4080f5e44de7df2df30b1de7d825cbcfe5054e26078fdc3c4f06432431a502c
  • openssh-askpass-8.0p1-10.el8.tuxcare.els10.x86_64.rpm
    sha:c7af2b37cb477fcea4d9e183f940a0b7e332bcea823735a93d11e7363d00a189
  • openssh-cavs-8.0p1-10.el8.tuxcare.els10.x86_64.rpm
    sha:ec95bee221d7cb849795ea0abee269f9828d44a45badc6c4a3cad1de8cb2d64f
  • openssh-clients-8.0p1-10.el8.tuxcare.els10.x86_64.rpm
    sha:96a209811fc9a9c963b783010dd23e62606f902c289ae82ce0c9a3e9e640b7ad
  • openssh-keycat-8.0p1-10.el8.tuxcare.els10.x86_64.rpm
    sha:e48211166c776dce250f61419c43a40e84572a9e15976b113fc81bf6d77c558b
  • openssh-ldap-8.0p1-10.el8.tuxcare.els10.x86_64.rpm
    sha:1ad4bd2b2267015122ca225e244a92b93be907c6fb35645d25094ac2c0d470d8
  • openssh-server-8.0p1-10.el8.tuxcare.els10.x86_64.rpm
    sha:96de9a8210697ad838a94126fc652ec7bf48d44fd6609e5ddc0b84103a66662f
  • pam_ssh_agent_auth-0.10.3-7.10.el8.tuxcare.els10.x86_64.rpm
    sha:e075a3871f82774dfbceeb53c9b02ac30982deee531b31963f63dda73d0a0aa5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.