-
Tue May 19 2026 EL Errata <el-errata_ww@oracle.com> - 9.9p1-23.0.1
- Upstream references found with /usr/bin/ssh [Orabug: 37824421]
-
Mon Apr 13 2026 Zoltan Fridrich <zfridric@redhat.com> - 9.9p1-23
- CVE-2026-35385: Fix privilege escalation via scp legacy protocol
when not in preserving file mode
Resolves: RHEL-164739
- CVE-2026-35388: Add connection multiplexing confirmation for proxy-mode
multiplexing sessions
Resolves: RHEL-166238
- CVE-2026-35387: Fix incomplete application of PubkeyAcceptedAlgorithms
and HostbasedAcceptedAlgorithms with regard to ECDSA keys
Resolves: RHEL-166222
- CVE-2026-35414: Fix mishandling of authorized_keys principals option
Resolves: RHEL-166190
- CVE-2026-35386: Add validation rules to usernames and hostnames
set for ProxyJump/-J on the commandline
Resolves: RHEL-166206
-
Thu Mar 26 2026 Zoltan Fridrich <zfridric@redhat.com> - 9.9p1-22
- Version bump
-
Mon Mar 16 2026 Zoltan Fridrich <zfridric@redhat.com> - 9.9p1-21
- CVE-2026-3497: Fix information disclosure or denial of service due
to uninitialized variables in gssapi-keyex
Resolves: RHEL-155812
-
Wed Feb 25 2026 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-20
- Provide a way to skip unsupported ML-KEM hybrid algorithms in FIPS mode
Resolves: RHEL-151579
-
Thu Dec 11 2025 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-19
- Support of hybrid MLKEM key exchange methods in FIPS mode
Resolves: RHEL-125929
-
Fri Dec 05 2025 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-18
- Adding a mechanism to disable GSSAPIDelegateCredentials in sshd_config
Resolves: RHEL-5281
-
Fri Dec 05 2025 Zoltan Fridrich <zfridric@redhat.com> - 9.9p1-17
- CVE-2025-61984: Reject usernames with control characters
Resolves: RHEL-128399
- CVE-2025-61985: Reject URL-strings with NULL characters
Resolves: RHEL-128388
-
Mon Nov 03 2025 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-16
- Implement mlkem768nistp256-sha256 and mlkem1024nistp384-sha384 KEX methods
Resolves: RHEL-70824
-
Mon Oct 27 2025 Zoltan Fridrich <zfridric@redhat.com> - 9.9p1-15
- Fix implicit destination path selection when source path ends with ".."
Resolves: RHEL-118406
- Canonicalize username when matching a user
Resolves: RHEL-101440