[CLSA-2026:1785317563] Fix CVE(s): CVE-2026-59999
Type:
security
Severity:
Important
Release date:
2026-07-29 09:32:54 UTC
Description:
* SECURITY UPDATE: DisableForwarding did not override PermitTunnel - debian/patches/CVE-2026-59999.patch: reject tunnel-device forwarding requests in server_request_tun() (serverloop.c) when DisableForwarding is set, so it takes precedence over PermitTunnel. - CVE-2026-59999
CVEs fixed:
Updated packages:
  • openssh-client_7.9p1-10+deb10u4+tuxcare.els5_amd64.deb
    sha:ca58b3a88c1f8b951ef1525144cd9b988a2f252f
  • openssh-server_7.9p1-10+deb10u4+tuxcare.els5_amd64.deb
    sha:106239ad28a121b60ad19b5c6de101bc623aeaae
  • openssh-sftp-server_7.9p1-10+deb10u4+tuxcare.els5_amd64.deb
    sha:263a677efa79a8a46cbd68b17bd52ebd623a9cf5
  • openssh-tests_7.9p1-10+deb10u4+tuxcare.els5_amd64.deb
    sha:be97e0eb21ad783f3f2ac2107246f9fbcfdffb71
  • ssh_7.9p1-10+deb10u4+tuxcare.els5_all.deb
    sha:7002641ca4496c4bdcce35efd1be46fff528716f
  • ssh-askpass-gnome_7.9p1-10+deb10u4+tuxcare.els5_amd64.deb
    sha:2a3a0b5212c1bc7950a9565e69fc272db657af2c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.