[CLSA-2026:1777465438] openssh: Fix of CVE-2026-35414
Type:
security
Severity:
Important
Release date:
2026-04-29 14:18:41 UTC
Description:
- CVE-2026-35414: fix incorrect matching of the authorized_keys principals="" option against certificate principals containing comma characters
Updated packages:
  • openssh-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:b66f53348bb6b4f70acfcf18d2be43963353290c8982b653c2bd4727f5cafc63
  • openssh-askpass-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:44412df1fba9ea48d138729f852e5f01d00e333bc1b2074e1b9eacfff1f08c43
  • openssh-cavs-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:c82b9c61439ed7cc1aee5fde68c17a50ed89630b63e68b45d4dfc4c508d32dea
  • openssh-clients-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:95cac06b6c024730086467ef72b193f4b08c4e1d51d3920c6b2fc6f5ed427dfe
  • openssh-keycat-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:16cfb0951c9ffcf73977828e2e8edf309d06272f2a6121790d66f039d3b72d38
  • openssh-ldap-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:4283acdbdd0d31cc32fb17d70e2224879ef222fc1be0b42b9531eb5e27bcc4f1
  • openssh-server-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:606841e23e6b42934e02f0ab90fd793254bc1ce8eb2645b8f4845b01a3b12167
  • openssh-server-sysvinit-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:7c5c998e7485ca62c9615c417094bdc8b1acf2f1c4e7b8bda7c704bc9810ad39
  • pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.tuxcare.els4.i686.rpm
    sha:c78610427618f8b009e4488f55a928d7cf44fc2d99180ce6794dbd5cb784d918
  • pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:1d5d23d724474cc50cd4473c796695fe3e410863ccfd435b21a2143d11d478d4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.