[CLSA-2026:1777393442] openssh: Fix of CVE-2026-35414
Type:
security
Severity:
Important
Release date:
2026-04-28 16:24:06 UTC
Description:
- CVE-2026-35414: fix incorrect matching of principals in the authorized_keys principals="..." option when a certificate principal contains a comma character
Updated packages:
  • openssh-8.0p1-24.el8.tuxcare.els6.x86_64.rpm
    sha:08b06353df2371a894eb72afcc00ae6255b0f8c06101c37803146b1d2309b119
  • openssh-askpass-8.0p1-24.el8.tuxcare.els6.x86_64.rpm
    sha:da51ba4a2c3130b92255286e46a18a999bd1c16fed179b647da9104712f994f4
  • openssh-cavs-8.0p1-24.el8.tuxcare.els6.x86_64.rpm
    sha:b409fb801909cbf8a5aa3a7d0d633f145b487ba629d4e3220d1b445e3640a4e9
  • openssh-clients-8.0p1-24.el8.tuxcare.els6.x86_64.rpm
    sha:b51e41b655badcae1c3f15b418f2c5880951c589e46d551d580d0d0f2e6ba3d9
  • openssh-keycat-8.0p1-24.el8.tuxcare.els6.x86_64.rpm
    sha:ede4f0f896e62986f852cbcf1a2065f2728d725a181f08938296edfd4faa3d4f
  • openssh-ldap-8.0p1-24.el8.tuxcare.els6.x86_64.rpm
    sha:d7b73e1dd370dfaa47f7489cb97d2b39b227fd40cbe49e8e27c03adcd2e7e3b1
  • openssh-server-8.0p1-24.el8.tuxcare.els6.x86_64.rpm
    sha:064df87da2555b828305d6c5be46f9106e43340f2f5f60d4ab28d29822ea8abe
  • pam_ssh_agent_auth-0.10.3-7.24.el8.tuxcare.els6.x86_64.rpm
    sha:2019d9e92932b180cf30759e497e7bc97f164ded9bcf9e2258b0733104d045ee
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.