Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:20126 - Security Advisory
Issued:
2025-11-11
Updated:
2025-11-11

RHSA-2025:20126 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: openssh security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for openssh is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.

Security Fix(es):

  • openssh: OpenSSH SSHD Agent Forwarding and X11 Forwarding (CVE-2025-32728)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 10 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2358767 - CVE-2025-32728 openssh: OpenSSH SSHD Agent Forwarding and X11 Forwarding
  • RHEL-58252 - OpenSSH should not use its own implementation of MLKEM
  • RHEL-68124 - Provide details on crypto error instead of "error in libcrypto" for non-supported private keys
  • RHEL-68346 - latest openssh in rhel10 causes issues with ssh and sshd system roles
  • RHEL-40790 - [RFE] Support for authentication indicators in OpenSSH
  • RHEL-93957 - [RfE] Please make it possible to opt out from the new ssh help message (RHEL 9.6)

CVEs

  • CVE-2025-32728

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/10.1_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
openssh-9.9p1-11.el10.src.rpm SHA-256: 48810ccaaedd2a792574a819d480afd30b4bab29393c851427622f35247e5a2d
x86_64
openssh-9.9p1-11.el10.x86_64.rpm SHA-256: c6b55fe45e79f657839330d6bf41f115c303de9377091ff7e79c23d9d5c7c74b
openssh-askpass-9.9p1-11.el10.x86_64.rpm SHA-256: 6f997fee5acdf68da75fef0947aae0bf3c2e5ef243f77756a4ac6547e2d5afc0
openssh-askpass-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: c58a583f9456ce088088d088613c49932968a7ff01384d39b770b746d83f1b6c
openssh-askpass-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: c58a583f9456ce088088d088613c49932968a7ff01384d39b770b746d83f1b6c
openssh-clients-9.9p1-11.el10.x86_64.rpm SHA-256: 68d6d9ffb2d4ea8dfd5c736f177d7b2de30e26e67b7c7e9f028d714d6cefa81e
openssh-clients-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: 8f34d05a832af623920a254a17eab5f10f1b31f73da039bb7d21df5acf509621
openssh-clients-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: 8f34d05a832af623920a254a17eab5f10f1b31f73da039bb7d21df5acf509621
openssh-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: 61cc2a7a3a426ae1f6766df7529d19fbf891c14b11eb3ed385fbca3ef12fd295
openssh-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: 61cc2a7a3a426ae1f6766df7529d19fbf891c14b11eb3ed385fbca3ef12fd295
openssh-debugsource-9.9p1-11.el10.x86_64.rpm SHA-256: 2e48d75ee30d73e2fda2d8286001d6e508eaa43b4f23b17a46fe3448c9e7f74e
openssh-debugsource-9.9p1-11.el10.x86_64.rpm SHA-256: 2e48d75ee30d73e2fda2d8286001d6e508eaa43b4f23b17a46fe3448c9e7f74e
openssh-keycat-9.9p1-11.el10.x86_64.rpm SHA-256: ef823b69fdab798d78ded7099206c777de1b80b457929b9c10fb0aa4abf027fb
openssh-keycat-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: 5788e8835003eb1ee9dfff1f6c122db69a18fdd48209e0eebab8feda01850826
openssh-keycat-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: 5788e8835003eb1ee9dfff1f6c122db69a18fdd48209e0eebab8feda01850826
openssh-keysign-9.9p1-11.el10.x86_64.rpm SHA-256: 60b79d6023046fcb10ba0007ead35b5cba37de6a022fb916767072cc6184ce72
openssh-keysign-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: 7dbce20ec360654f9f6400fefb33bb4d18e1764b94ee4a0fcce6cfe1a0429e9f
openssh-keysign-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: 7dbce20ec360654f9f6400fefb33bb4d18e1764b94ee4a0fcce6cfe1a0429e9f
openssh-server-9.9p1-11.el10.x86_64.rpm SHA-256: 7811e59bc758eca6c3e970a9ec706aaaa509304a4eea4a656a37705ec4d519d5
openssh-server-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: 5e63cb1d7e6c7858f20228d2c1a3930129f6c19dccf1b3bbd6dd68598d37bdd2
openssh-server-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: 5e63cb1d7e6c7858f20228d2c1a3930129f6c19dccf1b3bbd6dd68598d37bdd2
openssh-sk-dummy-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: 51c26ae02586f7979c706b0844d37d2edbf6122f1a6f620e3e288cadbf158797
openssh-sk-dummy-debuginfo-9.9p1-11.el10.x86_64.rpm SHA-256: 51c26ae02586f7979c706b0844d37d2edbf6122f1a6f620e3e288cadbf158797

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
openssh-9.9p1-11.el10.src.rpm SHA-256: 48810ccaaedd2a792574a819d480afd30b4bab29393c851427622f35247e5a2d
s390x
openssh-9.9p1-11.el10.s390x.rpm SHA-256: 6d82e344d66f81f78c4e5bbf7e97f97bd8d0edd6922e7b4a857695c479f9a32b
openssh-askpass-9.9p1-11.el10.s390x.rpm SHA-256: 6ff94744ad7e988101c428605ce32b848836b618840fab2e32eca72aad0987a0
openssh-askpass-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: 8ac3ea61606c5e169ca288d90411a345e8d3a2f2f40d97f02ed81c4b909e7f90
openssh-askpass-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: 8ac3ea61606c5e169ca288d90411a345e8d3a2f2f40d97f02ed81c4b909e7f90
openssh-clients-9.9p1-11.el10.s390x.rpm SHA-256: 6c6fb64b8a708662c4ccb8d7ef3d5a61f621b53689e8703c8e08c28cfa76e292
openssh-clients-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: fe613095e13273c6013d32786a7ac5dae1e0da7381156fff30c2e024cae60a24
openssh-clients-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: fe613095e13273c6013d32786a7ac5dae1e0da7381156fff30c2e024cae60a24
openssh-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: fd80d48a8309dba01179e8bf5bb18e2e1f2178323beeea01189e34dad26fcf60
openssh-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: fd80d48a8309dba01179e8bf5bb18e2e1f2178323beeea01189e34dad26fcf60
openssh-debugsource-9.9p1-11.el10.s390x.rpm SHA-256: 1c96df82ed3261e96d381a00465cc41cde29d8c8e99cdb3d4fe901d7ee835deb
openssh-debugsource-9.9p1-11.el10.s390x.rpm SHA-256: 1c96df82ed3261e96d381a00465cc41cde29d8c8e99cdb3d4fe901d7ee835deb
openssh-keycat-9.9p1-11.el10.s390x.rpm SHA-256: acb647cba0799a2899489f3da7a601e3b08399eeb6d71a2acfdb712250c5351b
openssh-keycat-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: 924843d608cf63df08bd8433a9474130f6b94e5950f1f809787d9f0f7cfd36e6
openssh-keycat-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: 924843d608cf63df08bd8433a9474130f6b94e5950f1f809787d9f0f7cfd36e6
openssh-keysign-9.9p1-11.el10.s390x.rpm SHA-256: d8eaa814d2ab27b3553ff367e1f77a1e926328a06b5ef9c8442409dd4c8d7ef0
openssh-keysign-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: 5ddab7d8e73cba6c7d1929f686491644fa0b353a133ceffd035a7debc560c948
openssh-keysign-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: 5ddab7d8e73cba6c7d1929f686491644fa0b353a133ceffd035a7debc560c948
openssh-server-9.9p1-11.el10.s390x.rpm SHA-256: ebe6528f497b24bd9a726a171aca3a899646ccec12524f086947a612edfac0d1
openssh-server-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: a1ea530bfbf2d91dfbf8e375c76b48b2aba4284ad2768f151e87de7c614c240d
openssh-server-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: a1ea530bfbf2d91dfbf8e375c76b48b2aba4284ad2768f151e87de7c614c240d
openssh-sk-dummy-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: 527ab3ff9f281bef4edddca149a7a8278c1820891fb577034e2203f2976775b6
openssh-sk-dummy-debuginfo-9.9p1-11.el10.s390x.rpm SHA-256: 527ab3ff9f281bef4edddca149a7a8278c1820891fb577034e2203f2976775b6

Red Hat Enterprise Linux for Power, little endian 10

SRPM
openssh-9.9p1-11.el10.src.rpm SHA-256: 48810ccaaedd2a792574a819d480afd30b4bab29393c851427622f35247e5a2d
ppc64le
openssh-9.9p1-11.el10.ppc64le.rpm SHA-256: 489770ee87577ce5416b003154d37cd785a8be4b82c0b1e098deea9b614e02be
openssh-askpass-9.9p1-11.el10.ppc64le.rpm SHA-256: 482579ce410b210cca49fea74f7d4f8f29550021c2f52c57af5b97a92f345332
openssh-askpass-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: ac6a274ddcfa9d938aee76dff06f56e24cfe871a4b9e129ff4e4ff250ef77dc6
openssh-askpass-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: ac6a274ddcfa9d938aee76dff06f56e24cfe871a4b9e129ff4e4ff250ef77dc6
openssh-clients-9.9p1-11.el10.ppc64le.rpm SHA-256: 50be78b073c61ca4d893cf4c9d29d334ceade976af8589ebed9984bc82c92c2d
openssh-clients-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: 215da8813d33c26513ed4979743072386713a41c0cd1476c645d3fc4e99341f8
openssh-clients-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: 215da8813d33c26513ed4979743072386713a41c0cd1476c645d3fc4e99341f8
openssh-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: 53124e792606f12af41af3cd55f61792efc630bebd5e23482273aa13829d4208
openssh-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: 53124e792606f12af41af3cd55f61792efc630bebd5e23482273aa13829d4208
openssh-debugsource-9.9p1-11.el10.ppc64le.rpm SHA-256: ad138a4206b97187fae75cf9bb8e39e6dc43aa22cb196e3b7779141570638b7d
openssh-debugsource-9.9p1-11.el10.ppc64le.rpm SHA-256: ad138a4206b97187fae75cf9bb8e39e6dc43aa22cb196e3b7779141570638b7d
openssh-keycat-9.9p1-11.el10.ppc64le.rpm SHA-256: 680c16f28f68f4330db4cdad2094d09edd1013853b882343ce6898d06a4c1de0
openssh-keycat-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: c712232a5bd57229c05257b98ed076e613be5201fce8a9d0b8d9f58db1775092
openssh-keycat-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: c712232a5bd57229c05257b98ed076e613be5201fce8a9d0b8d9f58db1775092
openssh-keysign-9.9p1-11.el10.ppc64le.rpm SHA-256: eda0c84ff365e1809d60fb89ec9fbe3517f31bd6c0484e2567d582430c3b2fd9
openssh-keysign-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: f9d196536868db6970d94cad79fb718cedb3063067d72b6c4b2120a23ae8ab57
openssh-keysign-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: f9d196536868db6970d94cad79fb718cedb3063067d72b6c4b2120a23ae8ab57
openssh-server-9.9p1-11.el10.ppc64le.rpm SHA-256: 38331a5f039f686ee330b6cac8141a2950a80fa9e2be532213ed293af2df72f2
openssh-server-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: 59ab18540092621029e246a9135e33a0cd919425bf53d61e25309673cfebef53
openssh-server-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: 59ab18540092621029e246a9135e33a0cd919425bf53d61e25309673cfebef53
openssh-sk-dummy-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: 88ce3c3c538619e786550a9bde2df3a3f540a5d9d17e3a39cf78c90be4f94e15
openssh-sk-dummy-debuginfo-9.9p1-11.el10.ppc64le.rpm SHA-256: 88ce3c3c538619e786550a9bde2df3a3f540a5d9d17e3a39cf78c90be4f94e15

Red Hat Enterprise Linux for ARM 64 10

SRPM
openssh-9.9p1-11.el10.src.rpm SHA-256: 48810ccaaedd2a792574a819d480afd30b4bab29393c851427622f35247e5a2d
aarch64
openssh-9.9p1-11.el10.aarch64.rpm SHA-256: c495be09d11ab0c68c3dd33689159c70ff8593dc818b8fc85dc282de76e0d5c0
openssh-askpass-9.9p1-11.el10.aarch64.rpm SHA-256: 1a5c243a3a53c4578e1aad803e42835ee608bbccf382455b57566f741a51381b
openssh-askpass-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: 7b1340afb134f258d44ad3fd55c8b4602306b7eaa9f62011b4ba7be2cc387418
openssh-askpass-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: 7b1340afb134f258d44ad3fd55c8b4602306b7eaa9f62011b4ba7be2cc387418
openssh-clients-9.9p1-11.el10.aarch64.rpm SHA-256: ada88f315931f7c15101a554db698d044db43bf8ca151649c650e43960fd45ef
openssh-clients-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: 4702ddede097a4a7f9e743c88de86b453e5b3b467fbd81d47a16c588996f5053
openssh-clients-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: 4702ddede097a4a7f9e743c88de86b453e5b3b467fbd81d47a16c588996f5053
openssh-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: b2668f7f2571cf8b854f24af3f2256dcfbed207fb468fc63cd9bd7e2eb759d45
openssh-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: b2668f7f2571cf8b854f24af3f2256dcfbed207fb468fc63cd9bd7e2eb759d45
openssh-debugsource-9.9p1-11.el10.aarch64.rpm SHA-256: f4792e224ba9748b9bfaae98af3991b0975965f2bfc7241663a38a73a1205520
openssh-debugsource-9.9p1-11.el10.aarch64.rpm SHA-256: f4792e224ba9748b9bfaae98af3991b0975965f2bfc7241663a38a73a1205520
openssh-keycat-9.9p1-11.el10.aarch64.rpm SHA-256: 3c19a6db614c66202319d1ec1d0be2fcf9b8fdfb584992259e137a3ccfe3cad2
openssh-keycat-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: a2dbb34805f86ed2546ec5f331568075bfca586730efae6671170bcaba17d4e6
openssh-keycat-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: a2dbb34805f86ed2546ec5f331568075bfca586730efae6671170bcaba17d4e6
openssh-keysign-9.9p1-11.el10.aarch64.rpm SHA-256: 417cde37d88cea211e97e81e67ce1a35447a72ec32dc4972f6fa91745e30bc03
openssh-keysign-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: 8cf4a0792923192a78d43b4cd2d16456c97cc1231e31decece227a7958761596
openssh-keysign-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: 8cf4a0792923192a78d43b4cd2d16456c97cc1231e31decece227a7958761596
openssh-server-9.9p1-11.el10.aarch64.rpm SHA-256: 953fed7c9a8c37fd6a099fd7f4d41dddd7fb19deb86851661833148470a1c971
openssh-server-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: 4a67856a39bdbaa369aa5592a03fcdab28d510903a6a8828e50845988e141683
openssh-server-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: 4a67856a39bdbaa369aa5592a03fcdab28d510903a6a8828e50845988e141683
openssh-sk-dummy-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: 523d86b950bdc9422e770cc34fa43147a3e10d8bf5e0df539c7248acb5a69b81
openssh-sk-dummy-debuginfo-9.9p1-11.el10.aarch64.rpm SHA-256: 523d86b950bdc9422e770cc34fa43147a3e10d8bf5e0df539c7248acb5a69b81

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility