#1144192 openssh: CVE-2026-73281 CVE-2026-73282 CVE-2026-73283

Package:
src:openssh
Source:
src:openssh
Submitter:
Salvatore Bonaccorso
Date:
2026-08-14 14:49:02 UTC
Severity:
normal
Tags:
#1144192#5
Date:
2026-08-12 06:25:15 UTC
From:
To:
Hi,

The following vulnerabilities were published for openssh.

CVE-2026-73281[0]:
| In ssh-agent in OpenSSH before 10.5, some operations can occur
| remotely but were intended to occur only locally, including
| operations that add tokens or use keys. This is caused by
| misinteraction between agent locking and the session-
| bind@openssh.com extension.


CVE-2026-73282[1]:
| In ssh in OpenSSH before 10.5, a use-after-free for realloc data can
| occur if a certain pair of remote-forwarding operations are
| concurrent.


CVE-2026-73283[2]:
| In sshd in OpenSSH before 10.5, the restrict keyword (in
| authorized_keys) was supposed to be applicable to tunnel forwarding
| but was not.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-73281
https://www.cve.org/CVERecord?id=CVE-2026-73281
[1] https://security-tracker.debian.org/tracker/CVE-2026-73282
https://www.cve.org/CVERecord?id=CVE-2026-73282
[2] https://security-tracker.debian.org/tracker/CVE-2026-73283
https://www.cve.org/CVERecord?id=CVE-2026-73283
[3] https://www.openwall.com/lists/oss-security/2026/08/12/1
[4] https://www.openssh.org/releasenotes.html#10.5

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144192#10
Date:
2026-08-14 14:46:42 UTC
From:
To:
Thanks.  FWIW I'm waiting for openssh-gssapi to get through NEW (and
ideally into testing) before I deal with this.