Collected every two hours from specialised publications — each link leads to the original article.
MGASA-2026-0059 - Updated openssh packages fix security vulnerabilities
Several security issues were fixed in OpenSSH.
Several security issues were fixed in OpenSSH.
Qualys researchers have recently identified two significant vulnerabilities in OpenSSH that put Linux and FreeBSD systems at severe risk. These bugs enable man…
Fix missing error codes set and invalid error code checks in OpenSSH. It prevents memory exhaustion attack and a MITM attack when VerifyHostKeyDNS is on (CVE-2…
Multiple vulnerabilities have been found in OpenSSH, the worst of which could allow a remote attacker to gain unauthorized access.
OpenSSH could be made to bypass the server identity check.
New openssh packages are available for Slackware 15.0 and -current to fix security issues.
Several security issues were fixed in OpenSSH.
The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS option is enab…
The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS option is enab…
The infamous OpenSSH "regreSSHion" vulnerability, CVE-2024-6387, sent shockwaves through the Linux security community when it was discovered this past summer. …
OpenSSH could be made to crash or run programs as your login if it received a specially crafted input.
The maintainers of the FreeBSD Project have released security updates to address a high-severity flaw in OpenSSH that attackers could potentially exploit to ex…
In an era where cybersecurity threats loom larger than ever, the discovery of a Remote Code Execution (RCE) vulnerability in OpenSSH by Qualys' Threat Research…
Select versions of the OpenSSH secure networking suite are susceptible to a new vulnerability that can trigger remote code execution (RCE).The vulnerability, t…
OpenSSH could be made to expose timing information over the network.
regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems. (CVE-2024-6387) References: - https://bugs.mageia.org/show_bug.cgi?id=33346
Backport fix for CVE-2024-6387 (rhbz#2294879) Backport fix for ObscureKeystrokeTiming logic error from OpenSSH 9.8
The package openssh before version 9.8p1-1 is vulnerable to authentication bypass.
A vulnerability has been discovered in OpenSSH, which can lead to remote code execution with root privileges.
OpenSSH could be made to bypass authentication and remotely access systems without proper credentials.
OpenSSH maintainers have released security updates to contain a critical security flaw that could result in unauthenticated remote code execution with root pri…
An update to OpenSSH , an open-source implementation of the Secure Shell (SSH) protocol, will introduce options to penalize unwanted behavior and increase secu…