|
|
Log in / Subscribe / Register

Ubuntu alert USN-8514-1 (openssh)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8514-1] OpenSSH vulnerability
Date:  Mon, 06 Jul 2026 15:11:28 +0000
Message-ID:  <E1wgkym-0003fa-M0@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8514-1 July 06, 2026 openssh vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: OpenSSH could be made to overwrite files as the administrator. Software Description: - openssh: secure shell (SSH) for secure access to remote machines Details: It was discovered that OpenSSH incorrectly handled file permissions when downloading files as root using the legacy scp protocol without the preserve-mode option. An attacker could use this to install setuid or setgid files on a system, possibly leading to privilege escalation. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS openssh-client 1:7.2p2-4ubuntu2.10+esm8 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8514-1 CVE-2026-35385


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpLxCwACgkQcpJm3tlz hgFG3g/+OPceB7t2dlc7C43h2g8QINLuimWZIrrohl+iUzGziDlqbz1oSsXOaG9U X5O9KxZk5jO3SY3BJwqRqoE2O7vFNz5wrvtDy0qgFaDoeNxvwXqeNjg/phkmHE18 pXL9S/3mJ++19h8J7y/4EIJG0qQLa5RE6RxS2NnSvEqvSge3K01yHXv/WR/n8zqY olS6ACOwelD8CRVM4w0dsgj6WL9veDhyP3YeMbPrCwtnVGOL/+INvBSb2Vu7qvPT 88GfFScsBh9jty7ecDTXNUGUGrsZpq0KEuk8+u8G1Olerb+pmp34wteo0rlJ+1OR m27hZsYLkIFi2uk4JfTgX1FA3Ojx466aay0vArzRMFeuklco/OwgT7ed7EAX7ZGF qzYf13IwYQt6iVcEug4OIoKHkCMb9HT7k3rM37Ds0MXaxwUdSBJiGm6xff+cxh0V ynliHe5Dbn9mCqW4d4oGC2lTtl5r0FCUWZsT8tGlU4IJKEBspVfQj3D04nU2tWyV ceZd8KdNBnN8HKCPdPj45UoCuHkkCkZy3zCCpyYS62avGxB38xlKBF1kUhNBEbJR UGUSIQNDz/WYWpD5RoaRhP80L2WogDvGhmjDgteIZUAn836URYVXLN1QJx1jBsbK h63pFbgWak6G1aHx6sbACE2v/lXW9B/j1mmgqNRkjP5ZYCZCCYo= =Z8+w -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds