Bug#1132576: openssh: CVE-2026-35414

Colin Watson <[email protected]> Fri, 1 May 2026 17:03:49 +0100
Newsgroups gmane.linux.debian.devel.ssh
Message-ID <afTO5Wjrq_PY6a6o__33186.2880777166$1777651524$gmane$org@riva.ucam.org>
On Fri, May 01, 2026 at 04:44:29PM +0200, Salvatore Bonaccorso wrote:
> On Thu, Apr 30, 2026 at 11:25:02AM +0100, Julian Gilbey wrote:
> > Surely this bug also affects stable, oldstable, ... and should be
> > fixed there via a security update too?  It doesn't appear to have
> > been.
> 
> Not via DSA, we tagged it no-dsa already. But a fix can go in (ideally
> with the other open CVEs marked no-dsa) in a upcoming point release.
> One is just around the corner, but I do not know if Colin has time for
> that.

Yeah, I'm working on backporting all the minor security fixes from 
10.3p1 to at least trixie and bookworm.  Possibly (E)LTS as well, since 
people do tend to worry about even minor security problems in OpenSSH.