🔧 ProgrammierungI have designed libraries professionally for 5 years(16.09.2026 um 20:58 Uhr)
🔧 ProgrammierungThe false choice between low-code and pro code(16.09.2026 um 21:00 Uhr)
🐧 Linux TippsI Deleted My Entire Security Stack. My Apps Got Safer.(16.09.2026 um 21:01 Uhr)
🔧 ProgrammierungComparing Four Practical Ways to Generate UUIDs at Work(16.09.2026 um 21:02 Uhr)
🔧 Programmierung# Power BI Data Modelling: A Great Path to Great Analysis(16.09.2026 um 21:05 Uhr)
🔧 ProgrammierungI have designed libraries professionally for 5 years(16.09.2026 um 20:58 Uhr)
🔧 ProgrammierungThe false choice between low-code and pro code(16.09.2026 um 21:00 Uhr)
🐧 Linux TippsI Deleted My Entire Security Stack. My Apps Got Safer.(16.09.2026 um 21:01 Uhr)
🔧 ProgrammierungComparing Four Practical Ways to Generate UUIDs at Work(16.09.2026 um 21:02 Uhr)
🔧 Programmierung# Power BI Data Modelling: A Great Path to Great Analysis(16.09.2026 um 21:05 Uhr)

🐧 Unix Server 🕛 vor 2 Monaten 2 Min Lesezeit CVE-2026-59995
0

USN-8533-1: OpenSSH vulnerabilities

Cyber Threat & Vulnerability Dossier CVSS 7.5 HIGH (Heuristik) EPSS 21.1%
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
Im CVE-Radar öffnen
↗ Quelle (ubuntu.com)
🗣️ Stimme:
It was discovered that OpenSSH sftp did not properly constrain the location
of downloaded files when connecting to an attacker-controlled server. An
attacker could possibly use this issue to write files to unintended
locations on the file system. (CVE-2026-59995)

It was discovered that OpenSSH scp could place files in the parent
directory of the intended destination when copying between two remote
hosts. An attacker could possibly use this issue to write files to
unintended locations. (CVE-2026-59996)

It was discovered that OpenSSH internal-sftp only recognized the first nine
command-line arguments, This could result in certain security-sensitive
arguments being ignored, contrary to expectations. (CVE-2026-59997)

It was discovered that OpenSSH had undocumented behaviour regarding the
GSSAPIStrictAcceptorCheck option in environments using Windows Active
Directory. The documentation has been updated to clarify use of the option.
(CVE-2026-59998)

It was discovered that OpenSSH did not properly enforce precedence of
DisableForwarding=yes over PermitTunnel=yes in server configurations. This
could possibly result in intended network forwarding restrictions being
bypassed, contrary to expectations. (CVE-2026-59999)

It was discovered that OpenSSH mishandled the MaxAuthTries limit for GSSAPI
authentication. A remote attacker could use this issue to perform excessive
authentication attempts. (CVE-2026-60000)

It was discovered that OpenSSH did not always honour the minimum
authentication delay. An attacker could possibly use this issue to perform
brute-force attacks more efficiently. (CVE-2026-60001)

It was discovered that the OpenSSH client had a use-after-free
vulnerability when a server changed its host key during a key re-exchange.
An attacker able to intercept communications could possibly use this issue
to execute arbitrary code or obtain sensitive information. (CVE-2026-60002)
Vollständiger Original-Artikel
Den kompletten Beitrag mit allen Details direkt auf ubuntu.com lesen.
↗ Original-Artikel auf ubuntu.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
9 Quellen
CVE-2022-44169 | Tenda AC15 15.03.05.18 formSetVirtualSer buffer overflow (EUVD-2022-47119)
1 Quelle
Best early October Prime Day deals: Save on TVs, smartwatches, and more tech
1 Quelle
I gave Claude Code $100 and 30 days to make a profit. Day 1, it built a product. Here's the pattern it used.
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten USN-8533-1: OpenSSH vulnerabilities

Thematisch verwandte Begriffe: USN85331, OpenSSH, vulnerabilities · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...