Collected every two hours from specialised publications — each link leads to the original article.
Fedora has released an update for OpenSSH version 10.2p1, addressing multiple CVEs related to security issues and vulnerabilities, which can be installed using…
Oracle Linux 9 has released updated packages for OpenSSH, addressing multiple security vulnerabilities through various fixes, including critical patches for re…
New OpenSSH packages for Slackware 15.0 and -current address security issues. Users can download updates and are advised to restart the sshd daemon after insta…
openSUSE released a security update for OpenSSH addressing eight vulnerabilities, including pre-authentication denial of service and improper file handling in …
New openssh packages are available for Slackware 15.0 and -current to fix security issues.
Important: openssh security update
Fix missing error codes set and invalid error code checks in OpenSSH. It prevents memory exhaustion attack and a MITM attack when VerifyHostKeyDNS is on (CVE-2…
Multiple vulnerabilities have been found in OpenSSH, the worst of which could allow a remote attacker to gain unauthorized access.
OpenSSH could be made to bypass the server identity check.
New openssh packages are available for Slackware 15.0 and -current to fix security issues.
Several security issues were fixed in OpenSSH.
The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS option is enab…
The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS option is enab…
OpenSSH could be made to crash or run programs as your login if it received a specially crafted input.
OpenSSH could be made to expose timing information over the network.
regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems. (CVE-2024-6387) References: - https://bugs.mageia.org/show_bug.cgi?id=33346
Backport fix for CVE-2024-6387 (rhbz#2294879) Backport fix for ObscureKeystrokeTiming logic error from OpenSSH 9.8
A vulnerability has been discovered in OpenSSH, which can lead to remote code execution with root privileges.
OpenSSH could be made to bypass authentication and remotely access systems without proper credentials.
* bsc#1251198 Cross-References: * CVE-2025-61984
* bsc#1186673 * bsc#1213004 * bsc#1213008 * bsc#1214788 * bsc#1216474
Machine-in-the-middle attack vulnerability if verifyhostkeydns is enabled. (CVE-2025-26465) References: - https://bugs.mageia.org/show_bug.cgi?id=34036