[CLSA-2026:1790070780] openssh: Fix of CVE-2026-73282
Type:
security
Severity:
Important
Release date:
2026-09-22 09:53:10 UTC
Description:
- CVE-2026-73282: pass the remote-forward index instead of a pointer into the reallocatable options.remote_forwards array to the global-confirm callback, fixing a use-after-free when a remote forward is added via the multiplexing socket while a confirmation is still pending (upstream 9910d5ef)
CVEs fixed:
Updated packages:
  • openssh-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:8a7d6a5c41d46cc28d6a8581b212439a8f5e99ba44aa72e7bc2e17e5192d833f
  • openssh-askpass-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:d9d0a524ad3ef1eaa57d29c8882a7c3e73c27cb6d7eb0510b685a9abbbf05e1e
  • openssh-cavs-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:acef52e2060d532aa8aeed18f812216a2160ae14b49248ebfa2cdcdd66e5e3ff
  • openssh-clients-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:86b1614a98e3465ef033935f589e21f27c5200627f5d7fc46fb003053eabebfa
  • openssh-keycat-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:813ae2a9611e96f3f06bcd2e29d69d6c66eb594a1334cc4c336c3d26ff1ba9db
  • openssh-ldap-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:2ec23236d6d80f59b55fdd6e3b6176a06ab4fdc5d24a96233c9b2cd028f37870
  • openssh-server-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:52d4e11f0f10ff180ff111f31630ef46c80f499921fd9aeab3280be243151aa8
  • openssh-server-sysvinit-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:599537abcbac97827705e951e098867013a773d4626d81c11879253cce0d420b
  • pam_ssh_agent_auth-0.10.3-2.23.0.5.el7_9.tuxcare.els2.i686.rpm
    sha:fc8da0b016a6dda60af772c0561d13fe0b90a400359a33bae1c3b2abde723046
  • pam_ssh_agent_auth-0.10.3-2.23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:c2db03c7a7d03615a394f562974c29e890b1907a0c00175a02b1996a9e657dcb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.