Skip to content

openssh: Fix CVE-2026-35414, CVE-2026-35388, CVE-2026-35387, CVE-2026-35386, CVE-2026-35385#14

Closed
deepin-ci-robot wants to merge 1 commit into
masterfrom
fix/openssh-cve-batch
Closed

openssh: Fix CVE-2026-35414, CVE-2026-35388, CVE-2026-35387, CVE-2026-35386, CVE-2026-35385#14
deepin-ci-robot wants to merge 1 commit into
masterfrom
fix/openssh-cve-batch

Conversation

@deepin-ci-robot
Copy link
Copy Markdown
Contributor

Security Update

Fixes the following CVEs:

Package

openssh

Changes

  • Upgrade to OpenSSH 10.3p1 upstream release
  • All 5 CVEs are fixed in this upstream release

Upstream

https://www.openssh.com/releasenotes.html#10.3p1

Testing

  • Build verification recommended
  • Security tests recommended

…-35388, CVE-2026-35387, CVE-2026-35386, CVE-2026-35385

Security fixes:
- CVE-2026-35414: Fix authorized_keys principals option handling
- CVE-2026-35388: Fix missing connection multiplexing confirmation
- CVE-2026-35387: Fix incomplete application of ECDSA algorithms
- CVE-2026-35386: Fix shell metacharacters validation in usernames
- CVE-2026-35385: Fix scp setuid/setgid bits handling

Upstream: https://www.openssh.com/releasenotes.html#10.3p1
@deepin-ci-robot deepin-ci-robot requested a review from myml April 15, 2026 08:05
@deepin-ci-robot
Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign zeno-sole for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@deepin-ci-robot
Copy link
Copy Markdown
Contributor Author

/hold
因为该quilt包的上游版本号变更,详情见: deepin-community/infra-settings#134

@github-actions
Copy link
Copy Markdown

TAG Bot

TAG: 1%10.3p1-1deepin1
EXISTED: no
DISTRIBUTION: unstable

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants