This update for openssh fixes the following issues:
Backported support for the mlkemx25519 key exchange from upstream (jsc#PED-16473).
CVE-2026-59995: sftp: location of downloaded files not properly constrained when sftp server:/path . is used with
an attacker-controlled server (bsc#1271044).
CVE-2026-59996: scp: file placed in the parent directory of an intended target directory when copy occurs between two remote destinations (bsc#1271046).
CVE-2026-59997: sshd: internal-sftp command lines are silently truncated after the 9th argument (bsc#1271048).
CVE-2026-59998: sshd: undocumented security-relevant GSSAPIStrictAcceptorCheck behavior in Windows Active Directory
is not documented (bsc#1271049).
CVE-2026-59999: sshd: DisableForwarding=yes does not override PermitTunnel=yes (bsc#1271052).
CVE-2026-60000: sshd: pre-authentication denial of service when GSSAPIAuthentication is enabled (bsc#1271053).
CVE-2026-60001: sshd: minimum authentication delay is not honored (bsc#1271054).
CVE-2026-60002: ssh: client-side use-after-free when a server changes its host key during a key reexchange (bsc#1271055).
{
"binaries": [
{
"openssh": "9.6p1-150600.6.49.1",
"openssh-clients": "9.6p1-150600.6.49.1",
"openssh-common": "9.6p1-150600.6.49.1",
"openssh-fips": "9.6p1-150600.6.49.1",
"openssh-helpers": "9.6p1-150600.6.49.1",
"openssh-server": "9.6p1-150600.6.49.1",
"openssh-server-config-disallow-rootlogin": "9.6p1-150600.6.49.1"
}
]
}{
"binaries": [
{
"openssh": "9.6p1-150600.6.49.1",
"openssh-askpass-gnome": "9.6p1-150600.6.49.1",
"openssh-clients": "9.6p1-150600.6.49.1",
"openssh-common": "9.6p1-150600.6.49.1",
"openssh-fips": "9.6p1-150600.6.49.1",
"openssh-helpers": "9.6p1-150600.6.49.1",
"openssh-server": "9.6p1-150600.6.49.1",
"openssh-server-config-disallow-rootlogin": "9.6p1-150600.6.49.1"
}
]
}{
"binaries": [
{
"openssh": "9.6p1-150600.6.49.1",
"openssh-askpass-gnome": "9.6p1-150600.6.49.1",
"openssh-clients": "9.6p1-150600.6.49.1",
"openssh-common": "9.6p1-150600.6.49.1",
"openssh-fips": "9.6p1-150600.6.49.1",
"openssh-helpers": "9.6p1-150600.6.49.1",
"openssh-server": "9.6p1-150600.6.49.1",
"openssh-server-config-disallow-rootlogin": "9.6p1-150600.6.49.1"
}
]
}{
"binaries": [
{
"openssh": "9.6p1-150600.6.49.1",
"openssh-askpass-gnome": "9.6p1-150600.6.49.1",
"openssh-clients": "9.6p1-150600.6.49.1",
"openssh-common": "9.6p1-150600.6.49.1",
"openssh-fips": "9.6p1-150600.6.49.1",
"openssh-helpers": "9.6p1-150600.6.49.1",
"openssh-server": "9.6p1-150600.6.49.1",
"openssh-server-config-disallow-rootlogin": "9.6p1-150600.6.49.1"
}
]
}{
"binaries": [
{
"openssh": "9.6p1-150600.6.49.1",
"openssh-askpass-gnome": "9.6p1-150600.6.49.1",
"openssh-clients": "9.6p1-150600.6.49.1",
"openssh-common": "9.6p1-150600.6.49.1",
"openssh-fips": "9.6p1-150600.6.49.1",
"openssh-helpers": "9.6p1-150600.6.49.1",
"openssh-server": "9.6p1-150600.6.49.1",
"openssh-server-config-disallow-rootlogin": "9.6p1-150600.6.49.1"
}
]
}