[CLSA-2026:1790071824] openssh: Fix of CVE-2026-73282
Type:
security
Severity:
Important
Release date:
2026-09-22 10:10:33 UTC
Description:
- CVE-2026-73282: pass the remote-forward index instead of a pointer into the reallocatable options.remote_forwards array to the global-confirm callback, fixing a use-after-free when a remote forward is added via the multiplexing socket while a confirmation is still pending (upstream 9910d5ef)
CVEs fixed:
Updated packages:
  • openssh-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:efb547d88ac647d047d8270302eac1cc0388433921ebeca4d2b9c64d5d547b1a
  • openssh-askpass-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:986dfefb8a9e38ae9635c8b92f88578aa73c2952749ee26a167179e3b701dbfc
  • openssh-cavs-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:5db30a66e767be4bc27f2291c3e0e0ccf3b73f35f12e18ad857c76b4cfe1e05d
  • openssh-clients-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:0647d8599144863962923791f3181919a5f0c5415b121314873c355cc74886b5
  • openssh-keycat-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:3c15da713b0b0706a06a234ea7f15ad585fffc8b6a2d8758a370ae381bcb4f9a
  • openssh-ldap-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:c773aed16a44de0537309af211fd89575e5bfbcbfb09781446aac88ab0bda9d1
  • openssh-server-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:f3ac95743e696655a40d496e9d9ea43f1d7e54dfe99b8c4a03048e2a9e0e3ab5
  • openssh-server-sysvinit-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:d9d7845ec7e6510b0a11135fd7efd84b99b4b2bd12cf73666dd2eba475f6b679
  • pam_ssh_agent_auth-0.10.3-2.23.0.5.el7_9.tuxcare.els2.i686.rpm
    sha:062b5ec6145b4c1e16ac91002b2d12dcc4947a551c467bdc836f9efdd3d6b443
  • pam_ssh_agent_auth-0.10.3-2.23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:a531d105305e89545a7267d649850596908717b444d11995d0d160f421410d93
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.