[CLSA-2026:1777466402] openssh: Fix of CVE-2026-35414
Type:
security
Severity:
Important
Release date:
2026-05-02 01:14:58 UTC
Description:
- CVE-2026-35414: fix incorrect matching of the authorized_keys principals="" option against certificate principals containing comma characters
Updated packages:
  • openssh-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:e717bdc1228a8840d49711088e88cb11d0e13cf63035073c2f16a85270935044
  • openssh-askpass-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:554d1f8c62794be16eccec5a9896a04a002c20767995a1f3fd7bb998007e0afa
  • openssh-cavs-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:3ab707015c002ddd46cd11caba1052161db5686213343be01d20203cd83dd39d
  • openssh-clients-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:600c09dcbaa6626a8acb22721c543bcd59bec31551df9368c26622019ecc7003
  • openssh-keycat-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:58294b07418a485fbdd782ad5ef5796e23c5847775eb862a70f37c1383e34689
  • openssh-ldap-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:6f219c67d65f773f5568123dc7f43640cdddd7bbd7a535b952d11c5a78c6e9f5
  • openssh-server-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:fcfcda90fc6bdc800b39bd8e5dab095452695784ac05555124644b61cab09aa5
  • openssh-server-sysvinit-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:fea2af8ccf282eeb411b98ad01a90e3c53462981680752ca065ba3699b0f0d7d
  • pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.tuxcare.els4.i686.rpm
    sha:1a3eb8c2a14a7b70022dd126f6d99e14dd18367a3fd00670acf566d773977c59
  • pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:868ecc94f58a53c9969465ec21977cd1d8ffb70f3b8d0874fbe8474d6e710ec1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.