Issued at: 2026-09-22
Updated at: 2026-09-22
Advisory content derived from Red Hat RHSA-2026:69266, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: openssh security, bug fix, and enhancement update
Description
OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.
Security Fix(es):
* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)
* openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)
* openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)
Bug Fix(es) and Enhancement(s):
* Incomplete backport of CVE-2023-38408 in Rocky Linux 8 openssh (JIRA:Rocky Linux-234763)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.