[CLSA-2026:1777504200] openssh: Fix of CVE-2026-35414
Type:
security
Severity:
Important
Release date:
2026-04-29 23:10:04 UTC
Description:
- CVE-2026-35414: fix incorrect matching of the authorized_keys principals="" option against certificate principals containing comma characters
Updated packages:
  • openssh-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:4b4b96eb5a128f6e548fe46e3fb496f51d10be469f389ef823eca5cbd497ef02
  • openssh-askpass-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:b242d1579dfac1e48a91d16f283f22acec140ea65625378729be31286eae2a7f
  • openssh-cavs-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:f5549d74d92c2d6c454442bd95200fa525bf87eff66af815ddd8be6bbe94310b
  • openssh-clients-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:c0c7217b6fd03044e4619957c59c4ccddd943a49af9ebe438d98a80dc0de42eb
  • openssh-keycat-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:82f30948b9a2378addabf96e64ee34460018d94f5605960c85297b703fa77432
  • openssh-ldap-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:12822d60fcb16605a0e7f4a1db6740c59997544602b013a7d1312ad6bf1215d2
  • openssh-server-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:0f5d63ac086dbd370b42f612ca8f4e39ed5c55a29799ca74bc9b331bdc66882f
  • openssh-server-sysvinit-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:58e7f28ed65459484123106b9487c45dac48458529949f04fa76866c6b93c820
  • pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.tuxcare.els4.i686.rpm
    sha:d3c18b3c74ebf63cd42280ee3024923307ccea2f1eb7312bff050288d4232d1e
  • pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:22ec80ffce9c111d15c3ea1b98cc7d2505d964a3827f42e1e97751977f84eb40
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.