{"id":"openSUSE-SU-2026:21477-1","summary":"Security update for openssh","details":"This update for openssh fixes the following issues:\n\n- CVE-2026-59995: sftp: location of downloaded files not properly constrained when `sftp server:/path .` is used with\n  an attacker-controlled server (bsc#1271044).\n- CVE-2026-59996: scp: file placed in the parent directory of an intended target directory when copy occurs between two\n  remote destinations (bsc#1271046).\n- CVE-2026-59997: sshd: `internal-sftp` command lines are silently truncated after the 9th argument (bsc#1271048).\n- CVE-2026-59998: sshd: undocumented security-relevant `GSSAPIStrictAcceptorCheck` behavior in Windows Active Directory\n  is not documented (bsc#1271049).\n- CVE-2026-59999: sshd: `DisableForwarding=yes` does not override `PermitTunnel=yes` (bsc#1271052).\n- CVE-2026-60000: sshd: pre-authentication denial of service when GSSAPIAuthentication is enabled (bsc#1271053).\n- CVE-2026-60001: sshd: minimum authentication delay is not honored (bsc#1271054).\n- CVE-2026-60002: ssh: client-side use-after-free when a server changes its host key during a key reexchange\n  (bsc#1271055).\n","modified":"2026-08-03T02:10:47.049588306Z","published":"2026-07-29T08:09:56Z","related":["CVE-2026-59995","CVE-2026-59996","CVE-2026-59997","CVE-2026-59998","CVE-2026-59999","CVE-2026-60000","CVE-2026-60001","CVE-2026-60002"],"upstream":["CVE-2026-59995","CVE-2026-59996","CVE-2026-59997","CVE-2026-59998","CVE-2026-59999","CVE-2026-60000","CVE-2026-60001","CVE-2026-60002"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271044"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271046"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271048"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271049"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271052"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271054"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271055"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59995"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59996"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59997"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59998"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59999"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-60000"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-60001"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-60002"}],"affected":[{"package":{"name":"openssh","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/openssh&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0p2-160000.7.1"}]}],"ecosystem_specific":{"binaries":[{"openssh-clients":"10.0p2-160000.7.1","openssh-common":"10.0p2-160000.7.1","openssh-helpers":"10.0p2-160000.7.1","openssh-server":"10.0p2-160000.7.1","openssh-server-config-rootlogin":"10.0p2-160000.7.1","openssh":"10.0p2-160000.7.1","openssh-askpass-gnome":"10.0p2-160000.7.1","openssh-cavs":"10.0p2-160000.7.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21477-1.json"}},{"package":{"name":"openssh-askpass-gnome","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/openssh-askpass-gnome&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0p2-160000.7.1"}]}],"ecosystem_specific":{"binaries":[{"openssh":"10.0p2-160000.7.1","openssh-askpass-gnome":"10.0p2-160000.7.1","openssh-cavs":"10.0p2-160000.7.1","openssh-clients":"10.0p2-160000.7.1","openssh-common":"10.0p2-160000.7.1","openssh-helpers":"10.0p2-160000.7.1","openssh-server":"10.0p2-160000.7.1","openssh-server-config-rootlogin":"10.0p2-160000.7.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21477-1.json"}}],"schema_version":"1.8.0"}