[ubuntu/resolute-security] openssh 1:10.2p1-2ubuntu3.4 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Mon Jul 13 12:42:21 UTC 2026


openssh (1:10.2p1-2ubuntu3.4) resolute-security; urgency=medium

  * SECURITY UPDATE: sftp downloaded files location issue
    - debian/patches/CVE-2026-59995.patch: upstream: avoid download to server-
      controlled path when performing in sftp.c.
    - CVE-2026-59995
  * SECURITY UPDATE: scp parent directory issue
    - debian/patches/CVE-2026-59996.patch: upstream: resist that return ".." via
      remote glob during in scp.c.
    - CVE-2026-59996
  * SECURITY UPDATE: internal-sftp ignores more than 9 commandline args
    - debian/patches/CVE-2026-59997.patch: upstream: pass >9 commandline
      arguments to the internal-sftp server, in session.c.
    - CVE-2026-59997
  * SECURITY UPDATE: undocumented GSSAPIStrictAcceptorCheck behaviour
    - debian/patches/CVE-2026-59998.patch: upstream: mention a caveat regarding
      GSSAPIStrictAcceptorCheck in in sshd_config.5.
    - CVE-2026-59998
  * SECURITY UPDATE: DisableForwarding=yes not taking proper precedence
    - debian/patches/CVE-2026-59999.patch: upstream: DisableForwarding=yes
      didn't override PermitTunnel=yes in serverloop.c.
    - CVE-2026-59999
  * SECURITY UPDATE: DoS via MaxAuthTries mishandling
    - debian/patches/CVE-2026-60000-1.patch: upstream: Fix multiple RFC 4462
      (GSSAPIAuthentication) compliance in auth2-gss.c.
    - debian/patches/CVE-2026-60000-2.patch: upstream: unused variables in
      auth2-gss.c.
    - CVE-2026-60000
  * SECURITY UPDATE: minimum authentication delay not always honoured
    - debian/patches/CVE-2026-60001.patch: upstream: Fix cases in GSSAPI and
      keyboard-interactive in auth.h, auth2-chall.c, auth2-gss.c, auth2.c.
    - CVE-2026-60001
  * SECURITY UPDATE: Use-after-free during a key re-exchange
    - debian/patches/CVE-2026-60002.patch: upstream: fix ownership and lifetime
      of several bits of client in ssh.c, sshconnect.c, sshconnect.h,
      sshconnect2.c.
    - CVE-2026-60002

openssh (1:10.2p1-2ubuntu3.3) resolute; urgency=medium

  * d/p/lp2151817-fix-pam-short-names-{1,2}.patch:
    - Cherry-pick upstream patch to fix PAM with short names (LP: #2151817)

Date: 2026-07-09 21:52:14.447904+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/openssh/1:10.2p1-2ubuntu3.4
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list