Bug#1132576: openssh: CVE-2026-35414
Julian Gilbey <[email protected]> Thu, 30 Apr 2026 11:25:02 +0100
| Newsgroups | gmane.linux.debian.devel.ssh |
|---|---|
| Message-ID | <afMt_gf1AX_uUSZH__9792.48935343406$1777544850$gmane$org@d-and-j.net> |
Hi! Surely this bug also affects stable, oldstable, ... and should be fixed there via a security update too? It doesn't appear to have been. Thanks, Julian On Fri, Apr 03, 2026 at 10:59:00AM +0200, Salvatore Bonaccorso wrote: > Source: openssh > Version: 1:10.2p1-6 > Severity: important > Tags: security upstream > X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> > > Hi, > > The following vulnerability was published for openssh. > > CVE-2026-35414[0]: > | OpenSSH before 10.3 mishandles the authorized_keys principals option > | in uncommon scenarios involving a principals list in conjunction > | with a Certificate Authority that makes certain use of comma > | characters. > > > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog entry. > > For further information see: > > [0] https://security-tracker.debian.org/tracker/CVE-2026-35414 > https://www.cve.org/CVERecord?id=CVE-2026-35414 > [1] https://www.openssh.org/releasenotes.html#10.3p1 > > Please adjust the affected versions in the BTS as needed. > > Regards, > Salvatore Julian