OESA-2026-3747

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3747
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3747.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3747
Upstream
Published
2026-09-14T16:33:57Z
Modified
2026-09-13T16:45:30Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
openssh security update
Details

An open source implementation of SSH protocol version 2

Security Fix(es):

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the (CVE-2026-73281)

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.(CVE-2026-73282)

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.(CVE-2026-73283)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:24.03-LTS-SP4 / openssh

Package

Name
openssh
Purl
pkg:rpm/openEuler/openssh&distro=openEuler-24.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.6p1-26.oe2403sp4

Ecosystem specific

{
    "aarch64": [
        "openssh-9.6p1-26.oe2403sp4.aarch64.rpm",
        "openssh-askpass-9.6p1-26.oe2403sp4.aarch64.rpm",
        "openssh-clients-9.6p1-26.oe2403sp4.aarch64.rpm",
        "openssh-debuginfo-9.6p1-26.oe2403sp4.aarch64.rpm",
        "openssh-debugsource-9.6p1-26.oe2403sp4.aarch64.rpm",
        "openssh-keycat-9.6p1-26.oe2403sp4.aarch64.rpm",
        "openssh-server-9.6p1-26.oe2403sp4.aarch64.rpm",
        "pam_ssh_agent_auth-0.10.4-5.26.oe2403sp4.aarch64.rpm"
    ],
    "noarch": [
        "openssh-help-9.6p1-26.oe2403sp4.noarch.rpm"
    ],
    "src": [
        "openssh-9.6p1-26.oe2403sp4.src.rpm"
    ],
    "x86_64": [
        "openssh-9.6p1-26.oe2403sp4.x86_64.rpm",
        "openssh-askpass-9.6p1-26.oe2403sp4.x86_64.rpm",
        "openssh-clients-9.6p1-26.oe2403sp4.x86_64.rpm",
        "openssh-debuginfo-9.6p1-26.oe2403sp4.x86_64.rpm",
        "openssh-debugsource-9.6p1-26.oe2403sp4.x86_64.rpm",
        "openssh-keycat-9.6p1-26.oe2403sp4.x86_64.rpm",
        "openssh-server-9.6p1-26.oe2403sp4.x86_64.rpm",
        "pam_ssh_agent_auth-0.10.4-5.26.oe2403sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3747.json"