[CLSA-2026:1790071932] openssh: Fix of CVE-2026-73282
Type:
security
Severity:
Important
Release date:
2026-09-22 11:22:09 UTC
Description:
- CVE-2026-73282: pass the remote-forward index instead of a pointer into the reallocatable options.remote_forwards array to the global-confirm callback, fixing a use-after-free when a remote forward is added via the multiplexing socket while a confirmation is still pending (upstream 9910d5ef)
CVEs fixed:
Updated packages:
  • openssh-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:d249912b0dd1990353650de163f637c06fcf1c202f7b6207bd38dfd879e3027e
  • openssh-askpass-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:cd72e1ca23354a5141ae79e19d4c490e2a4d59af4af7d6482e11b2eb639dca1d
  • openssh-cavs-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:51752dd230a5f5baef38c8229c4a689ba2ac3c04de89843bb00c40b1487b2fc3
  • openssh-clients-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:8c283fa142667844a422e4d40c7407d964308966f61dc226c372d43d67aecb75
  • openssh-keycat-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:dbac558eb08940f006802288cddda09dc8913807bce0e0751ac7526c5c05c179
  • openssh-ldap-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:ac5a32a8bbe5aa200155ee1910c25f1e77748c200a854acb91eb9789716b36e4
  • openssh-server-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:597367b9b376668d0fd86594920173be53e8cd3635833ea4e88cd6a891c714e3
  • openssh-server-sysvinit-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:a47b908fdbc0cf648a7541644b9d294973ca7daafbf8ab2844cf1aab3a80d9a2
  • pam_ssh_agent_auth-0.10.3-2.23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:7622f636e82adbefcdb416fa7a1e87ddf8b9dfb0e8d8f3ac40d1eac8b8b7d932
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.