An update for openssh is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX,
and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.
Security Fix(es):
* openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in
Red Hat Enterprise Linux OpenSSH client versions (CVE-2026-55655)
* openssh: Double free in Red Hat Enterprise Linux versions of OpenSSH DH-GEX
client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653)
* openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of
OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination (CVE-2026-55654)
* openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on
the client side (CVE-2026-60002)
* openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy
(CVE-2026-59996)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
CVE-2026-55653: Double Free (CWE-415)
CVE-2026-55654: Out-of-bounds Read (CWE-125)
CVE-2026-55655: Improper Restriction of Communication Channel to Intended
Endpoints (CWE-923)
CVE-2026-59996: Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal') (CWE-22)
CVE-2026-60002: Expired Pointer Dereference (CWE-825)
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Mehrere Probleme in openssh (Red Hat) | 0 | 10 | 30-07-2026 |
| 2 | Zwei Probleme in openssh (Red Hat) | 0 | 10 | 30-07-2026 |
| 3 | Mehrere Probleme in vim (Red Hat) | 0 | 10 | 30-07-2026 |
| 4 | Mehrere Probleme in libssh (SUSE) | 0 | 10 | 30-07-2026 |
| 5 | Mehrere Probleme in libssh (SUSE) | 0 | 10 | 30-07-2026 |
| 6 | Mehrere Probleme in nodejs24 (Red Hat) | 0 | 10 | 30-07-2026 |
| 7 | Zwei Probleme in python-pillow (Red Hat) | 0 | 26.67 | 30-07-2026 |
| 8 | Mehrere Probleme in samba (SUSE) | 0 | 10 | 30-07-2026 |
| 9 | Mehrere Probleme in nginx (SUSE) | 0 | 10 | 30-07-2026 |
| 10 | Zwei Probleme in gstreamer1-plugins-bad-free (Red Hat) | 0 | 10 | 30-07-2026 |