Уязвимость CVE-2026-35385: Информация

Описание

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

Важность: HIGH (8,1)
Вектор: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Опубликовано: 2 апреля 2026 г.
Изменено: 10 июля 2026 г.
Идентификатор типа ошибки: CWE-281

Исправленные пакеты

Имя пакета
Ветка
Исправлено в версии
Версия в репозитории
Errata ID
№ Задания
Состояние
dropbearsisyphus2026.91-alt12026.91-alt1ALT-PU-2026-7527-2417840Исправлено
dropbearsisyphus_riscv642026.91-alt12026.91-alt1ALT-PU-2026-7857-1-Исправлено
dropbearsisyphus_loongarch642026.91-alt12026.91-alt1ALT-PU-2026-7805-1-Исправлено
dropbear-muslsisyphus2026.91-alt12026.91-alt1ALT-PU-2026-7525-2417840Исправлено
dropbear-muslsisyphus_riscv642026.91-alt12026.91-alt1ALT-PU-2026-7855-1-Исправлено
dropbear-muslsisyphus_loongarch642026.91-alt12026.91-alt1ALT-PU-2026-7807-1-Исправлено

Ссылки на рекомендации, решения и инструменты

Ссылка
Ресурс
https://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2
  • Third Party Advisory
https://www.openssh.org/releasenotes.html#10.3p1
  • Release Notes
https://www.openwall.com/lists/oss-security/2026/04/02/3
  • Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:12389
    https://access.redhat.com/errata/RHSA-2026:13380
      https://access.redhat.com/errata/RHSA-2026:13381
        https://access.redhat.com/errata/RHSA-2026:13383
          https://access.redhat.com/errata/RHSA-2026:14937
            https://access.redhat.com/errata/RHSA-2026:16059
              https://access.redhat.com/errata/RHSA-2026:19069
                https://access.redhat.com/errata/RHSA-2026:19219
                  https://access.redhat.com/errata/RHSA-2026:20040
                    https://access.redhat.com/errata/RHSA-2026:21275
                      https://access.redhat.com/errata/RHSA-2026:21298
                        https://access.redhat.com/errata/RHSA-2026:21398
                          https://access.redhat.com/errata/RHSA-2026:22329
                            https://access.redhat.com/errata/RHSA-2026:22468
                              https://access.redhat.com/errata/RHSA-2026:22564
                                https://access.redhat.com/errata/RHSA-2026:22648
                                  https://access.redhat.com/errata/RHSA-2026:25044
                                    https://access.redhat.com/errata/RHSA-2026:25063
                                      https://access.redhat.com/errata/RHSA-2026:25096
                                        https://access.redhat.com/errata/RHSA-2026:25181
                                          https://access.redhat.com/errata/RHSA-2026:26528
                                            https://access.redhat.com/errata/RHSA-2026:26542
                                              https://access.redhat.com/errata/RHSA-2026:28887
                                                https://access.redhat.com/errata/RHSA-2026:28962
                                                  https://access.redhat.com/errata/RHSA-2026:30078
                                                    https://access.redhat.com/errata/RHSA-2026:30087
                                                      https://access.redhat.com/errata/RHSA-2026:30088
                                                        https://access.redhat.com/errata/RHSA-2026:30089
                                                          https://access.redhat.com/errata/RHSA-2026:34098
                                                            https://access.redhat.com/security/cve/CVE-2026-35385
                                                              https://bugzilla.redhat.com/show_bug.cgi?id=2454469
                                                                https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35385.json
                                                                    1. cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
                                                                      End excluding
                                                                      10.3