Bug#1132576: openssh: CVE-2026-35414

Julian Gilbey <[email protected]> Sun, 3 May 2026 08:35:28 +0100
Newsgroups gmane.linux.debian.devel.ssh
Message-ID <afb6wKt9obImzjbf__38973.4543090285$1777793847$gmane$org@d-and-j.net>
On Fri, May 01, 2026 at 05:03:49PM +0100, Colin Watson wrote:
> On Fri, May 01, 2026 at 04:44:29PM +0200, Salvatore Bonaccorso wrote:
> > On Thu, Apr 30, 2026 at 11:25:02AM +0100, Julian Gilbey wrote:
> > > Surely this bug also affects stable, oldstable, ... and should be
> > > fixed there via a security update too?  It doesn't appear to have
> > > been.
> > 
> > Not via DSA, we tagged it no-dsa already. But a fix can go in (ideally
> > with the other open CVEs marked no-dsa) in a upcoming point release.
> > One is just around the corner, but I do not know if Colin has time for
> > that.
> 
> Yeah, I'm working on backporting all the minor security fixes from 
> 10.3p1 to at least trixie and bookworm.  Possibly (E)LTS as well, since 
> people do tend to worry about even minor security problems in OpenSSH.

Amazing - thanks all!

Best wishes,

   Julian