[CLSA-2026:1790071218] openssh: Fix of CVE-2026-73282
Type:
security
Severity:
Important
Release date:
2026-09-22 10:00:27 UTC
Description:
- CVE-2026-73282: pass the remote-forward index instead of a pointer into the reallocatable options.remote_forwards array to the global-confirm callback, fixing a use-after-free when a remote forward is added via the multiplexing socket while a confirmation is still pending (upstream 9910d5ef)
CVEs fixed:
Updated packages:
  • openssh-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:c2aa361fa4fa6d580684a47619936f6381c040acdc2ed67eab406d32c18f94df
  • openssh-askpass-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:8ec94f5ec9d1074a9e0f876b0c22a0969ee8a83444d4572368ecc0915d5c2510
  • openssh-cavs-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:d04ae0b5d55ce0368e4a6379b939ddd69917535a8175461a8b1801bc1a6f9d32
  • openssh-clients-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:3e06e7ade0d6a4f7d5296b38aa8a97a0be05472a58a8f1026630cf780cce5315
  • openssh-keycat-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:ed2cd36fe817c313b2dc4f747a8b8b7b153eaafe1b957f860a1776b1789e44fa
  • openssh-ldap-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:fc6ba3939977770a57560681ea5b2b0ba4ecea902fc3353a2acd9fd044896e6f
  • openssh-server-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:3a1d381b6d5203b077f8a0a25bdceb2ae67be518e6151ca6ead0b1c58ba645e9
  • openssh-server-sysvinit-7.4p1-23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:0fc4ef9a8ec17d246cf7e716d69526f67a82765f9708e24d6c0c30aa5fa84cf1
  • pam_ssh_agent_auth-0.10.3-2.23.0.5.el7_9.tuxcare.els2.x86_64.rpm
    sha:2e499c207b26a689142ee9c215dea1a0b3b11a90f331ab34daf47db2715f5bb6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.