OpenSSH 10.3 Patches Command Execution and “scp” Privilege Escalation
ID: ca95b2ee-0129-5fe5-b0c9-30e06118ee4b
STIX ID: report--ca95b2ee-0129-5fe5-b0c9-30e06118ee4b
Feed Name: securityonline.info
OpenSSH 10.3 addresses multiple vulnerabilities including CVE-2026-35386 (improper validation of shell metacharacters in usernames that can enable client-side command execution when %u is expanded in ssh_config Match exec), CVE-2026-35385 (scp legacy mode failing to clear setuid/setgid bits when downloading as root, risking privilege escalation), CVE-2026-35414 (incorrect certificate principal matching when names contain commas), and fixes for ECDSA algorithm enforcement and multiplexing confirmation bypasses; administrators are advised to upgrade because some issues can enable command execution or privilege escalation under specific configurations, though no active exploitation is reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
