Red Hat Security Advisory: openssh security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-55653 — openssh: Double free in Red Hat Enterprise Linux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service
CVE-2026-55655 — openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Red Hat Enterprise Linux OpenSSH client versions
CVE-2026-59995 — openssh: OpenSSH: sftp client allows attacker to control downloaded file location
CVE-2026-59996 — openssh: OpenSSH: scp file misplacement vulnerability during remote copy
CVE-2026-59999 — openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options
CVE-2026-60001 — openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay
CVE-2026-73282 — openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client
🎯 Affected products91
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-0:9.9p1-7.el10_0.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-0:9.9p1-7.el10_0.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-0:9.9p1-7.el10_0.5.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-0:9.9p1-7.el10_0.5.src as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-0:9.9p1-7.el10_0.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-askpass-0:9.9p1-7.el10_0.5.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- openssh-askpass-0:9.9p1-7.el10_0.5.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- openssh-askpass-0:9.9p1-7.el10_0.5.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- openssh-askpass-0:9.9p1-7.el10_0.5.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- openssh-askpass-debuginfo-0:9.9p1-7.el10_0.5.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- openssh-askpass-debuginfo-0:9.9p1-7.el10_0.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-askpass-debuginfo-0:9.9p1-7.el10_0.5.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- openssh-askpass-debuginfo-0:9.9p1-7.el10_0.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-askpass-debuginfo-0:9.9p1-7.el10_0.5.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- openssh-askpass-debuginfo-0:9.9p1-7.el10_0.5.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-askpass-debuginfo-0:9.9p1-7.el10_0.5.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- openssh-askpass-debuginfo-0:9.9p1-7.el10_0.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-clients-0:9.9p1-7.el10_0.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-clients-0:9.9p1-7.el10_0.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-clients-0:9.9p1-7.el10_0.5.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-clients-0:9.9p1-7.el10_0.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-clients-debuginfo-0:9.9p1-7.el10_0.5.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- openssh-clients-debuginfo-0:9.9p1-7.el10_0.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-clients-debuginfo-0:9.9p1-7.el10_0.5.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- openssh-clients-debuginfo-0:9.9p1-7.el10_0.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-clients-debuginfo-0:9.9p1-7.el10_0.5.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- openssh-clients-debuginfo-0:9.9p1-7.el10_0.5.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
- openssh-clients-debuginfo-0:9.9p1-7.el10_0.5.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- +61 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, OpenSSH clients operating in FIPS mode should avoid negotiating the `diffie-hellman-group-exchange-sha256` key exchange algorithm. This can be achieved by explicitly listing allowed key exchange algorithms in the client's SSH configuration file (e.g., `/etc/ssh/ssh_config` or `~/.ssh/config`), ensuring `diffie-hellman-group-exchange-sha256` is *not* included. For example, to use a subset of common algorithms, you might configure: ``` KexAlgorithms [email protected],ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group14-sha1 ``` (Note: The above example `KexAlgorithms` list is illustrative and should be adjusted based on your environment's security requirements.) Additionally, avoid using non-fatal client flows, such as `ssh-keyscan`, against untrusted SSH servers while FIPS mode is enabled. Changes to `ssh_config` will take effect for new SSH connections. Workaround: To mitigate this issue, disable X11 forwarding on OpenSSH clients when it is not required. This can be achieved by avoiding the use of `-X` or `-Y` options when invoking `ssh`, or by setting `ForwardX11 no` in the SSH client configuration file (`~/.ssh/config` or `/etc/ssh/ssh_config`). Disabling X11 forwarding will prevent the client from attempting to establish X11 connections, thereby removing the attack vector. Workaround: To mitigate this issue, avoid using the `sftp server:/path .` command when connecting to untrusted or potentially malicious SFTP servers. Exercise caution and verify the authenticity of SFTP servers before initiating file transfers, especially when using commands that implicitly define the download destination, and also avoid running SFTP sessions with elevated privileges (such as root). Workaround: To mitigate this issue, users should avoid performing `scp` operations directly between two remote destinations. Instead, consider copying files from the first remote host to a local machine, and then from the local machine to the second remote host. Alternatively, use `sftp` or `rsync` for remote file transfers, as these utilities are not affected by this specific vulnerability. Workaround: To mitigate this issue, if `DisableForwarding=yes` is set in `/etc/ssh/sshd_config` to prevent all forwarding, ensure that `PermitTunnel` is explicitly set to `no` in the same configuration file. This will enforce the intended security policy. After modifying `/etc/ssh/sshd_config`, restart the `sshd` service for the changes to take effect. This may temporarily interrupt active SSH sessions. Workaround: Avoid issuing dynamic remote-forwarding commands over active SSH multiplexing connections, or disable socket multiplexing by setting ControlMaster no in ~/.ssh/config.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:76748
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2462250
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2462351
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2497927
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2497938
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2497942
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2497944
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2514328
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_76748.json