-
Tue Sep 29 2026 EL Errata <el-errata_ww@oracle.com> - 9.9p1-27.0.1
- Upstream references found with /usr/bin/ssh [Orabug: 37824421]
-
Fri Aug 21 2026 Zoltan Fridrich <zfridric@redhat.com> - 9.9p1-27
- CVE-2026-73283: Complete the fix of security bypass due to incorrect
handling of forwarding and tunneling options
Resolves: RHEL-245413
- CVE-2026-73281: Fix misinteraction between agent locking and
the session-bind@openssh.com extension
Resolves: RHEL-245423
- CVE-2026-73282: Fix information disclosure and data corruption
via use-after-free in ssh client
Resolves: RHEL-245418
-
Wed Aug 12 2026 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-26
- Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded
file location
Resolves: RHEL-236314
- Fix CVE-2026-59999 and CVE-2026-73283: Security bypass due to incorrect
handling of forwarding and tunneling options
Resolves: RHEL-236288
-
Tue Jul 14 2026 Zoltan Fridrich <zfridric@redhat.com> - 9.9p1-25
- CVE-2026-59996: Fix remote glob result of ".." causing files to be placed
in unintended parent directories when scp performs remote-to-remote copy
via the local host
Resolves: RHEL-193170
- CVE-2026-60002: Fix use-after-free in cached hostkey during key re-exchange
Resolves: RHEL-193016
-
Tue Jun 30 2026 Zoltan Fridrich <zfridric@redhat.com> - 9.9p1-24
- CVE-2026-55653: Fix double free in openssh DH-GEX client path during
FIPS known-group validation that leads to client-side denial of service
Resolves: RHEL-186435
- CVE-2026-55654: Fix heap out-of-bounds read during GSSAPI indicator
cleanup due to missing NULL terminator
Resolves: RHEL-185826
- CVE-2026-55655: Fix MITM of X11 forwarding via abstract UNIX socket
pre-binding
Resolves: RHEL-185852
-
Mon Apr 13 2026 Zoltan Fridrich <zfridric@redhat.com> - 9.9p1-23
- CVE-2026-35385: Fix privilege escalation via scp legacy protocol
when not in preserving file mode
Resolves: RHEL-164739
- CVE-2026-35388: Add connection multiplexing confirmation for proxy-mode
multiplexing sessions
Resolves: RHEL-166238
- CVE-2026-35387: Fix incomplete application of PubkeyAcceptedAlgorithms
and HostbasedAcceptedAlgorithms with regard to ECDSA keys
Resolves: RHEL-166222
- CVE-2026-35414: Fix mishandling of authorized_keys principals option
Resolves: RHEL-166190
- CVE-2026-35386: Add validation rules to usernames and hostnames
set for ProxyJump/-J on the commandline
Resolves: RHEL-166206
-
Thu Mar 26 2026 Zoltan Fridrich <zfridric@redhat.com> - 9.9p1-22
- Version bump
-
Mon Mar 16 2026 Zoltan Fridrich <zfridric@redhat.com> - 9.9p1-21
- CVE-2026-3497: Fix information disclosure or denial of service due
to uninitialized variables in gssapi-keyex
Resolves: RHEL-155812
-
Wed Feb 25 2026 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-20
- Provide a way to skip unsupported ML-KEM hybrid algorithms in FIPS mode
Resolves: RHEL-151579
-
Thu Dec 11 2025 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-19
- Support of hybrid MLKEM key exchange methods in FIPS mode
Resolves: RHEL-125929