ECHO-f8b1-1c2f-484d

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-f8b1-1c2f-484d.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-f8b1-1c2f-484d
Upstream
  • CVE-2026-106589
Withdrawn
2026-10-07T15:00:06Z
Published
2026-10-07T14:12:31Z
Modified
2026-10-07T15:45:04Z
Summary
QNX 6 / SCO OpenServer 5 only. sshd-session can keep root privileges on platforms that lack file-descriptor passing and need root for PTY allocation, via GatewayPorts and StreamLocalForwarding. Linux supports file-descriptor passing, so this code path is not used in Echo's build. OpenSSH 10.6 also forcibly disables those options on the affected platforms. https://www.openssh.com/releasenotes.html#10.6 https://security-tracker.debian.org/tracker/CVE-2026-106589
Details
References

Affected packages

Echo / openssh

Package

Name
openssh
Purl
pkg:deb/echo/openssh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:10.6p1-1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-f8b1-1c2f-484d.json"