Back to Security Advisories
High 2026-07-31

Openssh Security Update — AlmaLinux 9 (ALSA-2026:47756)

AlmaLinux 9

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server. Security Fix(es): * openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in AlmaLinux OpenSSH clien…

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.

Security Fix(es):

* openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in AlmaLinux OpenSSH clien…

Type:
security

Severity:
important

Release date:
2026-07-31

Description:
OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.

Security Fix(es):

* openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in AlmaLinux OpenSSH client versions (CVE-2026-55655)
* openssh: Double free in AlmaLinux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service (CVE-2026-55653)
* openssh: Heap out-of-bounds read in AlmaLinux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel termination (CVE-2026-55654)
* openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side (CVE-2026-60002)
* openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy (CVE-2026-59996)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 openssh-9.9p1-9.el9_8.alma.1.aarch64.rpm 28ce78fd36543ffdb669b9154214d21bb5965b263fd12ade22c561d6cd7157e4
aarch64 openssh-clients-9.9p1-9.el9_8.alma.1.aarch64.rpm 546f3a203368e23eb8b5eb7b80289986e34143c3c4216f41b905704aa715728d
aarch64 pam_ssh_agent_auth-0.10.4-7.9.el9_8.alma.1.aarch64.rpm a0782bc192e1da1c80f4a7623d61609035d6c317e1fe3dd62ab1866592f0c18b
aarch64 openssh-askpass-9.9p1-9.el9_8.alma.1.aarch64.rpm ab1f268397e1f908e51536016d09d207a65acd9333b216da4daaf2d69ba5e1c1
aarch64 openssh-server-9.9p1-9.el9_8.alma.1.aarch64.rpm c8abe4b55d1482d6bee1be0037833eab08b9ae860457340b888d9209e26d19b7
aarch64 openssh-keycat-9.9p1-9.el9_8.alma.1.aarch64.rpm cae011ed55f9621498b3cededcbf826df50a973326faca9850600567f006bf26
ppc64le openssh-server-9.9p1-9.el9_8.alma.1.ppc64le.rpm 3470fbdac6e127de3a71cf296c0e19015fce428d21624e04a9c0a4823821cb35
ppc64le openssh-askpass-9.9p1-9.el9_8.alma.1.ppc64le.rpm 7774b4c28089900a4e2d08d5174363f7b59c28322f58e19f94da28dbea8e5091
ppc64le openssh-9.9p1-9.el9_8.alma.1.ppc64le.rpm a496825651e4240137f7cbaa1e59ed2bc6363dac8ca7ad4fe94ce9290efb7ed6
ppc64le pam_ssh_agent_auth-0.10.4-7.9.el9_8.alma.1.ppc64le.rpm b359170e2227aec32b922714d51db51c5d91825e3ad940d3b18a9e6550c92314
ppc64le openssh-clients-9.9p1-9.el9_8.alma.1.ppc64le.rpm b4dfcd03f3f8648d84ce66c4c48e49622d2ff9ff60d2624ce9900f5d76731105
ppc64le openssh-keycat-9.9p1-9.el9_8.alma.1.ppc64le.rpm cf241c176509200d2abb1f5b124c7d5b76729966cd01799d01658d7d450be02b
s390x openssh-keycat-9.9p1-9.el9_8.alma.1.s390x.rpm 16b34402b14abe64e5672566f60b153201759cbf8af0719c595bc2abf6b625c0
s390x openssh-clients-9.9p1-9.el9_8.alma.1.s390x.rpm 5a832e0358ba001a60cba10a5200664687cb8fcbdfb418e7798d17607456233e
s390x openssh-server-9.9p1-9.el9_8.alma.1.s390x.rpm 76ecc097ebf958dfab0ea4874011b53049ab632b0f132ded258adeea9f3d5c7b
s390x openssh-9.9p1-9.el9_8.alma.1.s390x.rpm 8b0271d793424ca106fe3ff0c21bf0d40354227b871a50f0f9ed3f6db7e8cef5
s390x pam_ssh_agent_auth-0.10.4-7.9.el9_8.alma.1.s390x.rpm 939a416993c3b9272e0774b7296721457a4d8b14410f947fa96b6ff4d98de0ba
s390x openssh-askpass-9.9p1-9.el9_8.alma.1.s390x.rpm 9a9da8f3b3702042ff7bc6ba7b50d875abcc7969a09995e32bd13fd1df634739
x86_64 openssh-askpass-9.9p1-9.el9_8.alma.1.x86_64.rpm 5059b183da9b80ff8a3343e6d04993aaad9691e6a1d63b7070a4539cc632ac93
x86_64 pam_ssh_agent_auth-0.10.4-7.9.el9_8.alma.1.x86_64.rpm 9445a51a162e6d3e3e331f897114082455103ca528299953f871b0c91cc939a7
x86_64 openssh-9.9p1-9.el9_8.alma.1.x86_64.rpm 96d48b2a631313caf89453e36e677f54aa0d59c964f82d7aa84a0bd281c6ad37
x86_64 openssh-keycat-9.9p1-9.el9_8.alma.1.x86_64.rpm c678556e12b9010285264fe17de3d1dc87376ce3e3e44b9a3ca977b9bb97e7f1
x86_64 openssh-clients-9.9p1-9.el9_8.alma.1.x86_64.rpm e1e9916c61a6f7b38e72381da08e4fe57d89d9d5e7be0d8b90a41562cc75489c
x86_64 openssh-server-9.9p1-9.el9_8.alma.1.x86_64.rpm e49751e6b3d49648038243d5d6a3b1fe2bd3a146dd2d02fb69a62c2d34c89aeb

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System