UbuntuUpdates.org

Bugs fixes in "openssh"

Origin Bug number Title Date fixed
CVE CVE-2026-73281 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens 2026-09-03
CVE CVE-2026-73283 In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. 2026-09-03
CVE CVE-2026-73282 In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. 2026-09-03
CVE CVE-2026-73281 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens 2026-09-03
CVE CVE-2026-73283 In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. 2026-09-03
CVE CVE-2026-73282 In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. 2026-09-03
CVE CVE-2026-73281 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens 2026-09-03
CVE CVE-2026-73283 In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. 2026-09-03
CVE CVE-2026-73282 In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. 2026-09-03
CVE CVE-2026-73281 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens 2026-09-03
CVE CVE-2026-73283 In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. 2026-09-03
CVE CVE-2026-73282 In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. 2026-09-03
CVE CVE-2026-73281 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens 2026-09-03
CVE CVE-2026-73283 In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. 2026-09-03
CVE CVE-2026-73282 In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. 2026-09-03
CVE CVE-2026-73281 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens 2026-09-03
Launchpad 2161162 1:10.2p1-2ubuntu3.4 built without crypt() 2026-07-20
Launchpad 2161162 1:10.2p1-2ubuntu3.4 built without crypt() 2026-07-20
CVE CVE-2026-60002 ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the cl 2026-07-13
CVE CVE-2026-60001 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. 2026-07-13



About   -   Send Feedback to @ubuntu_updates