SUSE-SU-2025:20160-1

Source
https://www.suse.com/support/update/announcement/2025/suse-su-202520160-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:20160-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2025:20160-1
Upstream
Related
Published
2025-03-25T09:02:20Z
Modified
2026-03-23T04:50:04.239802Z
Summary
Security update for openssh
Details

This update for openssh fixes the following issues:

  • CVE-2025-26465: Fixed MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client (bsc#1237040).
  • CVE-2025-26466: Fixed DoS attack against OpenSSH's client and server (bsc#1237041).

Other bugfixes:

  • Fix ssh client segfault with GSSAPIKeyExchange=yes in ssh_kex2 due to gssapi proposal not being correctly initialized (bsc#1236826).
  • Add #include <stdlib.h> in some files added by the ldap patch to fix build with gcc14 (bsc#1225904).
  • Added missing struct initializer, added missing parameter (bsc#1222840).
  • Remove OPENSSLHAVEEVPGCM-ifdef, which is no longer supported by upstream (bsc#1221928).
  • Use %config(noreplace) for sshdconfig. In any case, it's recommended to drop a file in sshdconfig.d instead of editing sshd_config (bsc#1221063).
  • Add a patch to fix a regression introduced in 9.6 that makes X11 forwarding very slow (bsc#1229449).
  • Drop keycat binary that is not supported, except of the code that is used by other SELinux patches (bsc#1229072).
  • Fix RFC4256 implementation that keyboard-interactive authentication method can send instructions and sshd shows them to users (bsc#1229010).
  • Add attempts to mitigate instances of secrets lingering in memory after a session exits (bsc#1186673, bsc#1213004, bsc#1213008).
  • Remove empty line at the end of sshd-sle.pamd (bsc#1227456)
References

Affected packages

SUSE:Linux Micro 6.0 / openssh

Package

Name
openssh
Purl
pkg:rpm/suse/openssh&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.6p1-3.1

Ecosystem specific

{
    "binaries": [
        {
            "openssh-clients": "9.6p1-3.1",
            "openssh-common": "9.6p1-3.1",
            "openssh-server-config-rootlogin": "9.6p1-3.1",
            "openssh-server": "9.6p1-3.1",
            "openssh-fips": "9.6p1-3.1",
            "openssh": "9.6p1-3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:20160-1.json"