[CLSA-2026:1777466052] openssh: Fix of CVE-2026-35414
Type:
security
Severity:
Important
Release date:
2026-05-03 09:43:28 UTC
Description:
- CVE-2026-35414: fix incorrect matching of the authorized_keys principals="" option against certificate principals containing comma characters
Updated packages:
  • openssh-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:dedb31e6172dd85e375b8136fa523dcb6e06fd39e2fd52a948bfc01f485b17f3
  • openssh-askpass-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:49ef20c6e72c2617d4488b53924ade6d002ff091b679550aaea907b8c831d46e
  • openssh-cavs-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:765ea88e3d4b13fa2f91f45e89d7ac373cace1743f3421168295325a589afb52
  • openssh-clients-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:2ae74ff4d6781afb284746f54d9bc5a01e663d56f982b222645d3e0d343351b8
  • openssh-keycat-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:6ca29f3ed837a2a5f2eefc7f7fa000c800344b79b0006eee55557bac7725713e
  • openssh-ldap-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:48d878ef6aa65950c2f501a2491588762f53abb2a5a7b7f164684e63446443d6
  • openssh-server-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:8985100eb7daa0d3e7ce57c3b3d6a62166412335e25cf9af3fdd9b920d3484f9
  • openssh-server-sysvinit-7.4p1-23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:db7eb62c5397fed6bf9749736c9dc4b27408f73e9a0a5173f1d4046539c56c63
  • pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.tuxcare.els4.i686.rpm
    sha:1cfc9b38f1777ce635768aca3048922c73b289dfe1eea314de44875f56360d1c
  • pam_ssh_agent_auth-0.10.3-2.23.0.3.el7_9.tuxcare.els4.x86_64.rpm
    sha:929a6ae385c27afa1cb92d6ba2e53286ed0e3469e07bd1d8bd9ab7f63b79503b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.