USN-8804-1: OpenSSH vulnerabilities

Publication date

22 September 2026

Overview

Several security issues were fixed in OpenSSH.


Packages

  • openssh - secure shell (SSH) for secure access to remote machines

Details

Florian Kohnhäuser discovered that OpenSSH incorrectly handled shell
metacharacters in certain usernames. An attacker could possibly use this
issue to execute arbitrary commands when certain non-default
configurations were used, resulting in arbitrary code execution. This
issue only affected Ubuntu 14.04 LTS. (CVE-2026-35386)

Christos Papakonstantinou discovered that OpenSSH incorrectly handled
ECDSA algorithm restrictions. An attacker could possibly use this issue
to cause unintended ECDSA algorithms to be accepted, resulting in
security restrictions being bypassed. (CVE-2026-35387)

Vladimir Tokarev discovered that OpenSSH incorrectly handled certain
principal restrictions in authorized_keys files. An attacker could
possibly use this issue to bypass principal restrictions, resulting in
unauthorized access. This issue only affected Ubuntu 14.04 LTS,...

Florian Kohnhäuser discovered that OpenSSH incorrectly handled shell
metacharacters in certain usernames. An attacker could possibly use this
issue to execute arbitrary commands when certain non-default
configurations were used, resulting in arbitrary code execution. This
issue only affected Ubuntu 14.04 LTS. (CVE-2026-35386)

Christos Papakonstantinou discovered that OpenSSH incorrectly handled
ECDSA algorithm restrictions. An attacker could possibly use this issue
to cause unintended ECDSA algorithms to be accepted, resulting in
security restrictions being bypassed. (CVE-2026-35387)

Vladimir Tokarev discovered that OpenSSH incorrectly handled certain
principal restrictions in authorized_keys files. An attacker could
possibly use this issue to bypass principal restrictions, resulting in
unauthorized access. This issue only affected Ubuntu 14.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-35414)

It was discovered that OpenSSH incorrectly handled downloaded file paths
when using sftp with an untrusted server. An attacker could possibly use
this issue to write downloaded files outside the intended location,
resulting in unauthorized file modification. (CVE-2026-59995)

It was discovered that OpenSSH incorrectly handled command-line
arguments in internal-sftp. An attacker could possibly use this issue to
cause certain security-related arguments to be ignored, resulting in
security restrictions being bypassed. (CVE-2026-59997)

It was discovered that OpenSSH incorrectly handled
GSSAPIStrictAcceptorCheck when used with Windows Active Directory. An
attacker could possibly use this issue to bypass GSSAPI security
restrictions, resulting in unauthorized access. (CVE-2026-59998)

It was discovered that OpenSSH incorrectly handled forwarding
restrictions when DisableForwarding and PermitTunnel were used together.
An attacker could possibly use this issue to create tunnels despite
forwarding being disabled, resulting in security restrictions being
bypassed. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2026-59999)

It was discovered that OpenSSH incorrectly handled authentication
attempt limits when using GSSAPI authentication. An attacker could
possibly use this issue to consume excessive system resources, resulting
in a denial of service. (CVE-2026-60000)

It was discovered that OpenSSH did not always enforce the minimum
authentication delay. An attacker could possibly use this issue to
perform authentication attempts more rapidly than intended, resulting in
weakened brute-force protections. This issue only affected Ubuntu 20.04
LTS. (CVE-2026-60001)

It was discovered that OpenSSH incorrectly handled certain concurrent
remote forwarding operations. An attacker could possibly use this issue
to trigger a use-after-free, resulting in a denial of service or
arbitrary code execution. (CVE-2026-73282)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
20.04 LTS focal openssh-client –  1:8.2p1-4ubuntu0.13+esm3  
openssh-server –  1:8.2p1-4ubuntu0.13+esm3  
18.04 LTS bionic openssh-client –  1:7.6p1-4ubuntu0.7+esm6  
openssh-server –  1:7.6p1-4ubuntu0.7+esm6  
16.04 LTS xenial openssh-client –  1:7.2p2-4ubuntu2.10+esm10  
openssh-server –  1:7.2p2-4ubuntu2.10+esm10  
14.04 LTS trusty openssh-client –  1:6.6p1-2ubuntu2.13+esm4  
openssh-server –  1:6.6p1-2ubuntu2.13+esm4  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›