Hi,
The following vulnerabilities were published for openssh.
CVE-2026-73281[0]:
| In ssh-agent in OpenSSH before 10.5, some operations can occur
| remotely but were intended to occur only locally, including
| operations that add tokens or use keys. This is caused by
| misinteraction between agent locking and the session-
| bind@openssh.com extension.
CVE-2026-73282[1]:
| In ssh in OpenSSH before 10.5, a use-after-free for realloc data can
| occur if a certain pair of remote-forwarding operations are
| concurrent.
CVE-2026-73283[2]:
| In sshd in OpenSSH before 10.5, the restrict keyword (in
| authorized_keys) was supposed to be applicable to tunnel forwarding
| but was not.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-73281
https://www.cve.org/CVERecord?id=CVE-2026-73281
[1] https://security-tracker.debian.org/tracker/CVE-2026-73282
https://www.cve.org/CVERecord?id=CVE-2026-73282
[2] https://security-tracker.debian.org/tracker/CVE-2026-73283
https://www.cve.org/CVERecord?id=CVE-2026-73283
[3] https://www.openwall.com/lists/oss-security/2026/08/12/1
[4] https://www.openssh.org/releasenotes.html#10.5
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore