Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (8)
📋 Description
CVE-2026-59995 — openssh: OpenSSH: sftp client allows attacker to control downloaded file location
CVE-2026-59996 — openssh: OpenSSH: scp file misplacement vulnerability during remote copy
CVE-2026-59997 — openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw
CVE-2026-59998 — openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory
CVE-2026-59999 — openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options
CVE-2026-60000 — openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts
CVE-2026-60001 — openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay
CVE-2026-60002 — openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:37382
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-59996
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-59998
- externalhttps://access.redhat.com/security/cve/CVE-2026-60001
- externalhttps://access.redhat.com/security/cve/CVE-2026-60002
- externalhttps://access.redhat.com/security/cve/CVE-2026-59995
- externalhttps://access.redhat.com/security/cve/CVE-2026-59999
- externalhttps://access.redhat.com/security/cve/CVE-2026-59997
- externalhttps://access.redhat.com/security/cve/CVE-2026-60000
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_37382.json