Re: CVE-2026-73283 OpenSSH vulnerability
William Stewart via Cygwin <[email protected]>
| Newsgroups | gmane.os.cygwin |
|---|---|
| Message-ID | <CANV9t=R0u_mZha8x9oi8rF0zfzR3uAogHBn+S+vVY-+P7t+rGw@mail.gmail.com> |
On Tue, Aug 18, 2026 at 10:22 AM Ted Summers wrote: I would request another update to openssh to resolve CVE-2026-73283. The CVE description says: "In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not." (Also note that the "severity" is categorized as "low.") The release notes documenting this fix says the following: "sshd(8): make the authorized_keys 'restrict' keyword apply correctly to tunnel forwarding too (which is administratively disabled by default)." Note that the tunnel forwarding feature is administratively disabled by default. Thus, if you're not using tunnel forwarding, then there's not a need to update (if this is the sole purpose for updating). I'm not saying that the Cygwin team shouldn't update the package; that is certainly needed at some point relatively soon. I'm just saying that there's not an urgency to update if you're not using tunnel forwarding. -- Problem reports: https://cygwin.com/problems.html FAQ: https://cygwin.com/faq/ Documentation: https://cygwin.com/docs.html Unsubscribe info: https://cygwin.com/ml/#unsubscribe-simple