SUSE-SU-2026:3339-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263339-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3339-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3339-1
Upstream
CVE (4)
Related
Published
2026-07-28T10:03:18Z
Modified
2026-07-28T18:45:06Z
Summary
Security update for apache-sshd
Details

This update for apache-sshd fixes the following issues:

Update to upstream version 2.19.0.

Security issues fixed:

  • CVE-2026-56452: remote users can use SCP to send filenames that lead to arbitrary file writes due to a path traversal issue in the sshd-scp component of Apache MINA SSHD. (bsc#1272158).
  • CVE-2026-56623: remote users can obtain access to git repositories outside of the configured server-side root directory on Windows systems due to path traversal issue in org.apache.sshd:sshd-git (bsc#1271993).
  • CVE-2026-56624: users can authenticate with certificates containing the force-command option but still execute other commands due to improper validation of certificate options in Apache MINA SSHD (bsc#1271992).
  • CVE-2026-58624: remote execution of JGit commands can lead to arbitrary file writes due to improper input validation in sshd-git of Apache MINA SSHD (bsc#1271991).

Other updates and bugfixes:

  • Version 2.19.0:
    • Bug Fixes
      • GH-899 Fix ProcessShellFactory on Linux.
      • GH-902 Fix client-side handling of sk-* public key signatures (also in the agent interfaces).
      • Limit size of decompressed SSH packets.
      • Improve checking SSH user certificates in public-key authentication.
      • Improve handling of repository paths in sshd-git on Windows.
      • Validate file names in SCP.
      • Escape newlines in filenames in the SCP protocol.
      • Restrict JGit commands accessible via GitPgmCommandFactory in sshd-git.
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/suse/apache-sshd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.19.0-150200.5.16.1

Ecosystem specific

{
    "binaries":  [
        {
            "apache-sshd":  "2.19.0-150200.5.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3339-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/suse/apache-sshd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.19.0-150200.5.16.1

Ecosystem specific

{
    "binaries":  [
        {
            "apache-sshd":  "2.19.0-150200.5.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3339-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/suse/apache-sshd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.19.0-150200.5.16.1

Ecosystem specific

{
    "binaries":  [
        {
            "apache-sshd":  "2.19.0-150200.5.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3339-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/suse/apache-sshd&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.19.0-150200.5.16.1

Ecosystem specific

{
    "binaries":  [
        {
            "apache-sshd":  "2.19.0-150200.5.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3339-1.json"
SUSE:Linux Enterprise Module for Development Tools 15 SP7
apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/suse/apache-sshd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.19.0-150200.5.16.1

Ecosystem specific

{
    "binaries":  [
        {
            "apache-sshd":  "2.19.0-150200.5.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3339-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/suse/apache-sshd&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.19.0-150200.5.16.1

Ecosystem specific

{
    "binaries":  [
        {
            "apache-sshd":  "2.19.0-150200.5.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3339-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/suse/apache-sshd&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.19.0-150200.5.16.1

Ecosystem specific

{
    "binaries":  [
        {
            "apache-sshd":  "2.19.0-150200.5.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3339-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/suse/apache-sshd&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.19.0-150200.5.16.1

Ecosystem specific

{
    "binaries":  [
        {
            "apache-sshd":  "2.19.0-150200.5.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3339-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/suse/apache-sshd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.19.0-150200.5.16.1

Ecosystem specific

{
    "binaries":  [
        {
            "apache-sshd":  "2.19.0-150200.5.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3339-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/suse/apache-sshd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.19.0-150200.5.16.1

Ecosystem specific

{
    "binaries":  [
        {
            "apache-sshd":  "2.19.0-150200.5.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3339-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/suse/apache-sshd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.19.0-150200.5.16.1

Ecosystem specific

{
    "binaries":  [
        {
            "apache-sshd":  "2.19.0-150200.5.16.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3339-1.json"