{"id":"MGASA-2026-0193","summary":"Updated openssh packages fix security vulnerabilities","details":"In OpenSSH before 10.3, a file downloaded by scp may be installed setuid\nor setgid, an outcome contrary to some users' expectations, if the\ndownload is performed as root with -O (legacy scp protocol) and without\n-p (preserve mode). (CVE-2026-35385)\nIn OpenSSH before 10.3, command execution can occur via shell\nmetacharacters in a username within a command line. This requires a\nscenario where the username on the command line is untrusted, and also\nrequires a non-default configurations of % in ssh_config.\n(CVE-2026-35386)\nOpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any\nECDSA algorithm in PubkeyAcceptedAlgorithms or\nHostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA\nalgorithms. (CVE-2026-35387)\nOpenSSH before 10.3 omits connection multiplexing confirmation for\nproxy-mode multiplexing sessions. (CVE-2026-35388)\nOpenSSH before 10.3 mishandles the authorized_keys principals option in\nuncommon scenarios involving a principals list in conjunction with a\nCertificate Authority that makes certain use of comma characters.\n(CVE-2026-35414)\n","modified":"2026-06-10T17:15:04.754019969Z","published":"2026-06-10T17:11:15Z","upstream":["CVE-2026-35385","CVE-2026-35386","CVE-2026-35387","CVE-2026-35388","CVE-2026-35414"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0193.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35432"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UTBNRP3YCILEN5YUGOHA6V6DOMMOBMBJ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5G3QGTIHCK3F2NLJBFVZ56PCJ7RIYKLO/"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8222-1"}],"affected":[{"package":{"name":"openssh","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/openssh?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.3p1-2.7.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0193.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}