Release date:
2026-09-22 10:00:27 UTC
Description:
- CVE-2026-73282: pass the remote-forward index instead of a pointer into the
reallocatable options.remote_forwards array to the global-confirm callback,
fixing a use-after-free when a remote forward is added via the multiplexing
socket while a confirmation is still pending (upstream 9910d5ef)
Updated packages:
-
openssh-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:c2aa361fa4fa6d580684a47619936f6381c040acdc2ed67eab406d32c18f94df
-
openssh-askpass-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:8ec94f5ec9d1074a9e0f876b0c22a0969ee8a83444d4572368ecc0915d5c2510
-
openssh-cavs-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:d04ae0b5d55ce0368e4a6379b939ddd69917535a8175461a8b1801bc1a6f9d32
-
openssh-clients-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:3e06e7ade0d6a4f7d5296b38aa8a97a0be05472a58a8f1026630cf780cce5315
-
openssh-keycat-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:ed2cd36fe817c313b2dc4f747a8b8b7b153eaafe1b957f860a1776b1789e44fa
-
openssh-ldap-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:fc6ba3939977770a57560681ea5b2b0ba4ecea902fc3353a2acd9fd044896e6f
-
openssh-server-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:3a1d381b6d5203b077f8a0a25bdceb2ae67be518e6151ca6ead0b1c58ba645e9
-
openssh-server-sysvinit-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:0fc4ef9a8ec17d246cf7e716d69526f67a82765f9708e24d6c0c30aa5fa84cf1
-
pam_ssh_agent_auth-0.10.3-2.23.0.5.el7_9.tuxcare.els2.x86_64.rpm
sha:2e499c207b26a689142ee9c215dea1a0b3b11a90f331ab34daf47db2715f5bb6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.