[CLSA-2026:1777941528] openssh: Fix of CVE-2026-35385
Type:
security
Severity:
Important
Release date:
2026-05-05 00:38:55 UTC
Description:
- CVE-2026-35385: fix scp legacy protocol receiver to clear setuid/setgid bits from downloaded files when -p (preserve mode) is not set
Updated packages:
  • openssh-5.3p1-125.el6.tuxcare.els7.x86_64.rpm
    sha:fe4f93e68965c9d9488ded3486595980c0556f96bc7819602b6de464c1d06c9a
  • openssh-askpass-5.3p1-125.el6.tuxcare.els7.x86_64.rpm
    sha:5f9da5049f2c0b403dfc3c5b6542dba2f6d3430ceef6f18df073eddfd3f6d103
  • openssh-clients-5.3p1-125.el6.tuxcare.els7.x86_64.rpm
    sha:3516b361484f5614fcbe32f7d570dc8a8934a33521565eb04231dfe4f4f6e703
  • openssh-ldap-5.3p1-125.el6.tuxcare.els7.x86_64.rpm
    sha:07ae4878dee5874e9cf0eee5501654b0ce1ae61405412e05d897ff565b313bb0
  • openssh-server-5.3p1-125.el6.tuxcare.els7.x86_64.rpm
    sha:03655f926ab4c8e8dfd7f460e7ccf173e258fdece998e53e6c1b6d98631379c5
  • pam_ssh_agent_auth-0.9.3-125.el6.tuxcare.els7.i686.rpm
    sha:7325052cc08de4f55bdcfa54334d4ae53c197e6a45bdb274ab20f4a24723df1d
  • pam_ssh_agent_auth-0.9.3-125.el6.tuxcare.els7.x86_64.rpm
    sha:ea15f6d71ce046b5bd21c64969ebb9f07474f5cfd2e2f466c7d7984b0fccd82a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.