Collected every two hours from specialised publications — each link leads to the original article.
Important: openssh security update
Several security issues were fixed in OpenSSH.
OpenSSH could be made to overwrite files as the administrator.
Fedora has released an update for OpenSSH version 10.2p1, addressing multiple CVEs related to security issues and vulnerabilities, which can be installed using…
Oracle Linux 9 has released updated packages for OpenSSH, addressing multiple security vulnerabilities through various fixes, including critical patches for re…
Oracle Linux has released updated RPMs for version 8, addressing CVEs 2026-55653 and 2026-55655, which fix security vulnerabilities in OpenSSH affecting both x…
Oracle Linux has released updated OpenSSH packages for version 10, addressing multiple CVEs related to security vulnerabilities, including remote-to-remote cop…
openSUSE released a security update for OpenSSH addressing eight vulnerabilities, including pre-authentication denial of service and improper file handling in …
A critical security update for OpenSSH has been released for Rocky Linux 9, addressing multiple vulnerabilities including denial of service and risks associate…
An important security update for OpenSSH on Rocky Linux 10 addresses several vulnerabilities, including local MITM risks and denial of service threats, enhanci…
A security update for OpenSSH in Rocky Linux 8 addresses vulnerabilities including a local MITM attack and a client-side denial of service risk, classified as …
A security update for OpenSSH on Rocky Linux 8 addresses several vulnerabilities, including improper validation and character encoding issues, with enhancement…
OpenSSH could allow unintended access to network services.
CVE-2026-55653: Fix double free in openssh DH-GEX client path during FIPS known- group validation that leads to client-side denial of service CVE-2026-55654: F…
Improve GSS KEX algorithms documentation CVE-2026-55653: Fix double free in openssh DH-GEX client path during FIPS known- group validation that leads to client…
OpenSSH could be made to overwrite files as the administrator.
Jeremy Brown discovered a flaw in the GSSAPI Key Exchange patch applied in Debian to OpenSSH, an implementation of the SSH protocol suite, affecting non-defaul…
MGASA-2026-0059 - Updated openssh packages fix security vulnerabilities
Qualys researchers have recently identified two significant vulnerabilities in OpenSSH that put Linux and FreeBSD systems at severe risk. These bugs enable man…
Fix missing error codes set and invalid error code checks in OpenSSH. It prevents memory exhaustion attack and a MITM attack when VerifyHostKeyDNS is on (CVE-2…
Multiple vulnerabilities have been found in OpenSSH, the worst of which could allow a remote attacker to gain unauthorized access.
The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS option is enab…
The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS option is enab…
The infamous OpenSSH "regreSSHion" vulnerability, CVE-2024-6387, sent shockwaves through the Linux security community when it was discovered this past summer. …