{"id":"SUSE-SU-2026:21875-1","summary":"Security update for openssh","details":"This update for openssh fixes the following issues\n\n\n- CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427).\n- CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430).\n\nChanges for openssh:\n\n- Fix a potential issue when validating mac (bsc#1264568):\n","modified":"2026-06-03T18:24:40.147985529Z","published":"2026-05-28T15:02:16Z","related":["CVE-2026-35385","CVE-2026-35414"],"upstream":["CVE-2026-35385","CVE-2026-35414"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621875-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261427"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261430"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264568"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35385"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35414"}],"schema_version":"1.7.5"}