{"id":"SUSE-SU-2026:3605-1","summary":"Security update for openssh","details":"This update for openssh fixes the following issues:\n\n- Backported support for the mlkemx25519 key exchange from upstream (jsc#PED-16473).\n\n- CVE-2026-59995: sftp: location of downloaded files not properly constrained when `sftp server:/path .` is used with\n  an attacker-controlled server (bsc#1271044).\n- CVE-2026-59996: scp: file placed in the parent directory of an intended target directory when copy occurs between two\n  remote destinations (bsc#1271046).\n- CVE-2026-59997: sshd: `internal-sftp` command lines are silently truncated after the 9th argument (bsc#1271048).\n- CVE-2026-59998: sshd: undocumented security-relevant `GSSAPIStrictAcceptorCheck` behavior in Windows Active Directory\n  is not documented (bsc#1271049).\n- CVE-2026-59999: sshd: `DisableForwarding=yes` does not override `PermitTunnel=yes` (bsc#1271052).\n- CVE-2026-60000: sshd: pre-authentication denial of service when GSSAPIAuthentication is enabled (bsc#1271053).\n- CVE-2026-60001: sshd: minimum authentication delay is not honored (bsc#1271054).\n- CVE-2026-60002: ssh: client-side use-after-free when a server changes its host key during a key reexchange\n  (bsc#1271055).\n","modified":"2026-08-14T10:30:36.331891225Z","published":"2026-08-13T06:35:44Z","related":["CVE-2026-59995","CVE-2026-59996","CVE-2026-59997","CVE-2026-59998","CVE-2026-59999","CVE-2026-60000","CVE-2026-60001","CVE-2026-60002"],"upstream":["CVE-2026-59995","CVE-2026-59996","CVE-2026-59997","CVE-2026-59998","CVE-2026-59999","CVE-2026-60000","CVE-2026-60001","CVE-2026-60002"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263605-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271044"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271046"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271048"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271049"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271052"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271054"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271055"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59995"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59996"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59997"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59998"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59999"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-60000"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-60001"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-60002"}],"affected":[{"package":{"name":"openssh","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.6p1-150600.6.49.1"}]}],"ecosystem_specific":{"binaries":[{"openssh-helpers":"9.6p1-150600.6.49.1","openssh-server":"9.6p1-150600.6.49.1","openssh-server-config-disallow-rootlogin":"9.6p1-150600.6.49.1","openssh":"9.6p1-150600.6.49.1","openssh-clients":"9.6p1-150600.6.49.1","openssh-common":"9.6p1-150600.6.49.1","openssh-fips":"9.6p1-150600.6.49.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3605-1.json"}},{"package":{"name":"openssh-askpass-gnome","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP7","purl":"pkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.6p1-150600.6.49.1"}]}],"ecosystem_specific":{"binaries":[{"openssh-askpass-gnome":"9.6p1-150600.6.49.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3605-1.json"}},{"package":{"name":"openssh","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.6p1-150600.6.49.1"}]}],"ecosystem_specific":{"binaries":[{"openssh-askpass-gnome":"9.6p1-150600.6.49.1","openssh-clients":"9.6p1-150600.6.49.1","openssh-common":"9.6p1-150600.6.49.1","openssh-fips":"9.6p1-150600.6.49.1","openssh-helpers":"9.6p1-150600.6.49.1","openssh-server":"9.6p1-150600.6.49.1","openssh-server-config-disallow-rootlogin":"9.6p1-150600.6.49.1","openssh":"9.6p1-150600.6.49.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3605-1.json"}},{"package":{"name":"openssh-askpass-gnome","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.6p1-150600.6.49.1"}]}],"ecosystem_specific":{"binaries":[{"openssh-helpers":"9.6p1-150600.6.49.1","openssh-server":"9.6p1-150600.6.49.1","openssh-server-config-disallow-rootlogin":"9.6p1-150600.6.49.1","openssh":"9.6p1-150600.6.49.1","openssh-askpass-gnome":"9.6p1-150600.6.49.1","openssh-clients":"9.6p1-150600.6.49.1","openssh-common":"9.6p1-150600.6.49.1","openssh-fips":"9.6p1-150600.6.49.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3605-1.json"}},{"package":{"name":"openssh","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.6p1-150600.6.49.1"}]}],"ecosystem_specific":{"binaries":[{"openssh-server-config-disallow-rootlogin":"9.6p1-150600.6.49.1","openssh":"9.6p1-150600.6.49.1","openssh-askpass-gnome":"9.6p1-150600.6.49.1","openssh-clients":"9.6p1-150600.6.49.1","openssh-common":"9.6p1-150600.6.49.1","openssh-fips":"9.6p1-150600.6.49.1","openssh-helpers":"9.6p1-150600.6.49.1","openssh-server":"9.6p1-150600.6.49.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3605-1.json"}},{"package":{"name":"openssh-askpass-gnome","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/openssh-askpass-gnome&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.6p1-150600.6.49.1"}]}],"ecosystem_specific":{"binaries":[{"openssh-helpers":"9.6p1-150600.6.49.1","openssh-server":"9.6p1-150600.6.49.1","openssh-server-config-disallow-rootlogin":"9.6p1-150600.6.49.1","openssh":"9.6p1-150600.6.49.1","openssh-askpass-gnome":"9.6p1-150600.6.49.1","openssh-clients":"9.6p1-150600.6.49.1","openssh-common":"9.6p1-150600.6.49.1","openssh-fips":"9.6p1-150600.6.49.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3605-1.json"}}],"schema_version":"1.9.0"}