Re: CVE-2026-73283 OpenSSH vulnerability

William Stewart via Cygwin <[email protected]>
Newsgroups gmane.os.cygwin
Message-ID <CANV9t=R0u_mZha8x9oi8rF0zfzR3uAogHBn+S+vVY-+P7t+rGw@mail.gmail.com>
On Tue, Aug 18, 2026 at 10:22 AM Ted Summers wrote:

I would request another update to openssh to resolve CVE-2026-73283.


The CVE description says: "In sshd in OpenSSH before 10.5, the restrict
keyword (in authorized_keys) was supposed to be applicable to tunnel
forwarding but was not." (Also note that the "severity" is categorized as
"low.")

The release notes documenting this fix says the following: "sshd(8): make
the authorized_keys 'restrict' keyword apply correctly to tunnel forwarding
too (which is administratively disabled by default)."

Note that the tunnel forwarding feature is administratively disabled by
default. Thus, if you're not using tunnel forwarding, then there's not a
need to update (if this is the sole purpose for updating).

I'm not saying that the Cygwin team shouldn't update the package; that is
certainly needed at some point relatively soon. I'm just saying that
there's not an urgency to update if you're not using tunnel forwarding.

-- 
Problem reports:      https://cygwin.com/problems.html
FAQ:                  https://cygwin.com/faq/
Documentation:        https://cygwin.com/docs.html
Unsubscribe info:     https://cygwin.com/ml/#unsubscribe-simple
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.