Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:23480 - Security Advisory
Issued:
2025-12-17
Updated:
2025-12-17

RHSA-2025:23480 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: openssh security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for openssh is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.

Security Fix(es):

  • openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand (CVE-2025-61984)
  • openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand (CVE-2025-61985)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2401960 - CVE-2025-61984 openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand
  • BZ - 2401962 - CVE-2025-61985 openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand

CVEs

  • CVE-2025-61984
  • CVE-2025-61985

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
openssh-8.7p1-47.el9_7.src.rpm SHA-256: d05ad155b72ffe35154b872fc96a4afdb55d0f0cbe171022ff421f0a76725382
x86_64
openssh-8.7p1-47.el9_7.x86_64.rpm SHA-256: 9b81451b1f325139829ad9436890b42e23586feb15f4c7b2fa5c526854bf18cf
openssh-askpass-8.7p1-47.el9_7.x86_64.rpm SHA-256: cf47bcd8a86aea62833a1cdfa1440bb10c1827e8164a7f762b64d04b02610685
openssh-askpass-debuginfo-8.7p1-47.el9_7.x86_64.rpm SHA-256: f97e41d1ad47ea52068d8e5261c521b7ac50eb7d9fd2d767986a2e9eb5529807
openssh-askpass-debuginfo-8.7p1-47.el9_7.x86_64.rpm SHA-256: f97e41d1ad47ea52068d8e5261c521b7ac50eb7d9fd2d767986a2e9eb5529807
openssh-clients-8.7p1-47.el9_7.x86_64.rpm SHA-256: 8d6e1934d12df54433fbff8969b48599070da8e556a44606f7cf6227e679adca
openssh-clients-debuginfo-8.7p1-47.el9_7.x86_64.rpm SHA-256: cf8b1123e5ac888405ad0cbb53157f3a12cf3ffc0a0af96fff473e8c25d8f143
openssh-clients-debuginfo-8.7p1-47.el9_7.x86_64.rpm SHA-256: cf8b1123e5ac888405ad0cbb53157f3a12cf3ffc0a0af96fff473e8c25d8f143
openssh-debuginfo-8.7p1-47.el9_7.x86_64.rpm SHA-256: 89dd09bad65e6ef4967b8fce61372aa0acab18b0d6b4fc2c829d8460d08bd36d
openssh-debuginfo-8.7p1-47.el9_7.x86_64.rpm SHA-256: 89dd09bad65e6ef4967b8fce61372aa0acab18b0d6b4fc2c829d8460d08bd36d
openssh-debugsource-8.7p1-47.el9_7.x86_64.rpm SHA-256: c26b56eb5cddf88ab60445c372a6deda76e667d555688d6507bdd18139bc9c9b
openssh-debugsource-8.7p1-47.el9_7.x86_64.rpm SHA-256: c26b56eb5cddf88ab60445c372a6deda76e667d555688d6507bdd18139bc9c9b
openssh-keycat-8.7p1-47.el9_7.x86_64.rpm SHA-256: 9d9a3f91bd21a17b9fd6f34f61771129122ec38a8503bd3232ce84a7464623fb
openssh-keycat-debuginfo-8.7p1-47.el9_7.x86_64.rpm SHA-256: c035c0b331d38d9f544dd73aedcf4965c2d524722d04326db58791170ce4a3c8
openssh-keycat-debuginfo-8.7p1-47.el9_7.x86_64.rpm SHA-256: c035c0b331d38d9f544dd73aedcf4965c2d524722d04326db58791170ce4a3c8
openssh-server-8.7p1-47.el9_7.x86_64.rpm SHA-256: 6e4b1bcef8939636ce000dfad99fb12867e49f895ffa286468305b5ab9bf120d
openssh-server-debuginfo-8.7p1-47.el9_7.x86_64.rpm SHA-256: 2229fad1a276b760500143a632db5d308963c695f7ffabb7a6939c43076cade9
openssh-server-debuginfo-8.7p1-47.el9_7.x86_64.rpm SHA-256: 2229fad1a276b760500143a632db5d308963c695f7ffabb7a6939c43076cade9
openssh-sk-dummy-debuginfo-8.7p1-47.el9_7.x86_64.rpm SHA-256: 5430f264e2175aea272ada9919e476997f71bc9c830674f6449de8e36d95fbd2
openssh-sk-dummy-debuginfo-8.7p1-47.el9_7.x86_64.rpm SHA-256: 5430f264e2175aea272ada9919e476997f71bc9c830674f6449de8e36d95fbd2
pam_ssh_agent_auth-0.10.4-5.47.el9_7.x86_64.rpm SHA-256: e6222405c062fe4631ec43f66445c09a6ddf19dd22ffbe1eed5bf30a5ac01198
pam_ssh_agent_auth-debuginfo-0.10.4-5.47.el9_7.x86_64.rpm SHA-256: 6daf789492971c5f1d19ec3c404ecbb87098525b9cc325f7a4b918daac52f8e6
pam_ssh_agent_auth-debuginfo-0.10.4-5.47.el9_7.x86_64.rpm SHA-256: 6daf789492971c5f1d19ec3c404ecbb87098525b9cc325f7a4b918daac52f8e6

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
openssh-8.7p1-47.el9_7.src.rpm SHA-256: d05ad155b72ffe35154b872fc96a4afdb55d0f0cbe171022ff421f0a76725382
s390x
openssh-8.7p1-47.el9_7.s390x.rpm SHA-256: 304d07af2fd37c108dcbb16cb998211d78b4617bc366d263401daf58a272f07f
openssh-askpass-8.7p1-47.el9_7.s390x.rpm SHA-256: f0843282e6518606b73c6418140890757f264cf6eae30e48ddd6f3e68c6b53b2
openssh-askpass-debuginfo-8.7p1-47.el9_7.s390x.rpm SHA-256: 39b131f832dfae80649ef2debcbde088ff24408435647923b1bbbd244bb58d46
openssh-askpass-debuginfo-8.7p1-47.el9_7.s390x.rpm SHA-256: 39b131f832dfae80649ef2debcbde088ff24408435647923b1bbbd244bb58d46
openssh-clients-8.7p1-47.el9_7.s390x.rpm SHA-256: f8a9c90a9516ce6a5cff8b5d8122993fa37bc2539edc4557d63a0384862c95d0
openssh-clients-debuginfo-8.7p1-47.el9_7.s390x.rpm SHA-256: c81afe1642dc150f9d41e7c393b5cdadb8e0d53d2ebf8659cdd5f0277f7e73d8
openssh-clients-debuginfo-8.7p1-47.el9_7.s390x.rpm SHA-256: c81afe1642dc150f9d41e7c393b5cdadb8e0d53d2ebf8659cdd5f0277f7e73d8
openssh-debuginfo-8.7p1-47.el9_7.s390x.rpm SHA-256: b18db0856e8c4aa7b4bb011469601a1d162dd60b903363c9cc6696a67c5f06de
openssh-debuginfo-8.7p1-47.el9_7.s390x.rpm SHA-256: b18db0856e8c4aa7b4bb011469601a1d162dd60b903363c9cc6696a67c5f06de
openssh-debugsource-8.7p1-47.el9_7.s390x.rpm SHA-256: be7938f1922139f035edbbb7a8acd0b73b4a77bc170639075ec7a9ceef4b8f43
openssh-debugsource-8.7p1-47.el9_7.s390x.rpm SHA-256: be7938f1922139f035edbbb7a8acd0b73b4a77bc170639075ec7a9ceef4b8f43
openssh-keycat-8.7p1-47.el9_7.s390x.rpm SHA-256: e1de6a69d8da1ed5c8156bae82dfa307300e088b9a5003c88a7da02d16184f67
openssh-keycat-debuginfo-8.7p1-47.el9_7.s390x.rpm SHA-256: 3336362121720d0517a00b61035e1440f38a9eab680a3b4a0eb570a73348a0b3
openssh-keycat-debuginfo-8.7p1-47.el9_7.s390x.rpm SHA-256: 3336362121720d0517a00b61035e1440f38a9eab680a3b4a0eb570a73348a0b3
openssh-server-8.7p1-47.el9_7.s390x.rpm SHA-256: 1b1c88f2850f05b18c2521a478dd0de2e00301b7baa494f69101da0b82a38feb
openssh-server-debuginfo-8.7p1-47.el9_7.s390x.rpm SHA-256: d2a62966263a2aa99583154341378e15f6465ed1dcbd1030172870b4de02cf0b
openssh-server-debuginfo-8.7p1-47.el9_7.s390x.rpm SHA-256: d2a62966263a2aa99583154341378e15f6465ed1dcbd1030172870b4de02cf0b
openssh-sk-dummy-debuginfo-8.7p1-47.el9_7.s390x.rpm SHA-256: b3a10e69a1c058142672f886c89ddf2080d8fdf1ab2b8151c39a618261bac111
openssh-sk-dummy-debuginfo-8.7p1-47.el9_7.s390x.rpm SHA-256: b3a10e69a1c058142672f886c89ddf2080d8fdf1ab2b8151c39a618261bac111
pam_ssh_agent_auth-0.10.4-5.47.el9_7.s390x.rpm SHA-256: 36c9a615ce4f5155ce0e120a0ed1ae885a4ba834b8e432d7b2268600da1fb3cd
pam_ssh_agent_auth-debuginfo-0.10.4-5.47.el9_7.s390x.rpm SHA-256: 45d34dad7e1db7e7a91411b0b625e01ba03e29276117af66c02f6dcf71dc6470
pam_ssh_agent_auth-debuginfo-0.10.4-5.47.el9_7.s390x.rpm SHA-256: 45d34dad7e1db7e7a91411b0b625e01ba03e29276117af66c02f6dcf71dc6470

Red Hat Enterprise Linux for Power, little endian 9

SRPM
openssh-8.7p1-47.el9_7.src.rpm SHA-256: d05ad155b72ffe35154b872fc96a4afdb55d0f0cbe171022ff421f0a76725382
ppc64le
openssh-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 61f60d1c4e0fd54fbd9fe2cbb3a824af06837c4b925a603421cb84c74cdbe8ce
openssh-askpass-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 4e3cc8dd8b1bfe3a7dd03efc6286fef1226c23d99478bb106ad373c00da62d62
openssh-askpass-debuginfo-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 945688c83814838d89508a7adbdea1b91d6b67ec081ae4d20bfd5b181b7905f6
openssh-askpass-debuginfo-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 945688c83814838d89508a7adbdea1b91d6b67ec081ae4d20bfd5b181b7905f6
openssh-clients-8.7p1-47.el9_7.ppc64le.rpm SHA-256: f6c7c3a1408c0de2fa4eec2c6f53636cd71f0da730a87ec3e02051fe91e3976c
openssh-clients-debuginfo-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 9de8792cb3eafc5d08f8f00462cf0d487857e352fcdd598a9116910f7243e85b
openssh-clients-debuginfo-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 9de8792cb3eafc5d08f8f00462cf0d487857e352fcdd598a9116910f7243e85b
openssh-debuginfo-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 302fd0f4caa08edf04796099389bf7081865258a2281a7da151c52ae9f0611ef
openssh-debuginfo-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 302fd0f4caa08edf04796099389bf7081865258a2281a7da151c52ae9f0611ef
openssh-debugsource-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 1adc9d93970ae673d613b7d6875ad659e4bd8451e5dd5d971ba58cc169aaf97c
openssh-debugsource-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 1adc9d93970ae673d613b7d6875ad659e4bd8451e5dd5d971ba58cc169aaf97c
openssh-keycat-8.7p1-47.el9_7.ppc64le.rpm SHA-256: ad0737f3aad1bd795a01368b04f1b3938f835a72873a95162707788155d30840
openssh-keycat-debuginfo-8.7p1-47.el9_7.ppc64le.rpm SHA-256: b68255ef7f63cccabda4c400bf65848742af84a10949ebd9ce6efbbc7dd1fb41
openssh-keycat-debuginfo-8.7p1-47.el9_7.ppc64le.rpm SHA-256: b68255ef7f63cccabda4c400bf65848742af84a10949ebd9ce6efbbc7dd1fb41
openssh-server-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 780e46345f83c390e385b6d96464df251ea164cde341430c35739b265cfa8021
openssh-server-debuginfo-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 134eb14eff0b34571899ee81c2d96d450943aab4d27fa2bd451617feb5d3bb79
openssh-server-debuginfo-8.7p1-47.el9_7.ppc64le.rpm SHA-256: 134eb14eff0b34571899ee81c2d96d450943aab4d27fa2bd451617feb5d3bb79
openssh-sk-dummy-debuginfo-8.7p1-47.el9_7.ppc64le.rpm SHA-256: e7fa66861101ccab3058fcd503c5b057e6d6660d045493e3cf29483105f55057
openssh-sk-dummy-debuginfo-8.7p1-47.el9_7.ppc64le.rpm SHA-256: e7fa66861101ccab3058fcd503c5b057e6d6660d045493e3cf29483105f55057
pam_ssh_agent_auth-0.10.4-5.47.el9_7.ppc64le.rpm SHA-256: eb211e4ead90739628f128e5b78ce93947a4c0f3224c9cdd7835357c3765507c
pam_ssh_agent_auth-debuginfo-0.10.4-5.47.el9_7.ppc64le.rpm SHA-256: d7691149b6d7fa931214c51b7f954353987ed91305123c997d0a5e6d9619de67
pam_ssh_agent_auth-debuginfo-0.10.4-5.47.el9_7.ppc64le.rpm SHA-256: d7691149b6d7fa931214c51b7f954353987ed91305123c997d0a5e6d9619de67

Red Hat Enterprise Linux for ARM 64 9

SRPM
openssh-8.7p1-47.el9_7.src.rpm SHA-256: d05ad155b72ffe35154b872fc96a4afdb55d0f0cbe171022ff421f0a76725382
aarch64
openssh-8.7p1-47.el9_7.aarch64.rpm SHA-256: 80f3b5be41982ee637ffba3354170b4873c46c47460149c82f9821cd3a1ebf8e
openssh-askpass-8.7p1-47.el9_7.aarch64.rpm SHA-256: c9d207fbadf74f4d4dd2e5d5201bebeb1298c1e8a63ae697c4e09f6a3f6e4b7a
openssh-askpass-debuginfo-8.7p1-47.el9_7.aarch64.rpm SHA-256: 6e8a688fb9c8e7a6285db7b18ee74509de169dddbb69b880faf3a5d1700893a4
openssh-askpass-debuginfo-8.7p1-47.el9_7.aarch64.rpm SHA-256: 6e8a688fb9c8e7a6285db7b18ee74509de169dddbb69b880faf3a5d1700893a4
openssh-clients-8.7p1-47.el9_7.aarch64.rpm SHA-256: 5c294f4427bb2f80b699d6f8c6163659413b2821ac6db38cc8fa21c544694503
openssh-clients-debuginfo-8.7p1-47.el9_7.aarch64.rpm SHA-256: 3c091527d001d108dc1f044779bba76a683943458c8cf36a916777953ae51307
openssh-clients-debuginfo-8.7p1-47.el9_7.aarch64.rpm SHA-256: 3c091527d001d108dc1f044779bba76a683943458c8cf36a916777953ae51307
openssh-debuginfo-8.7p1-47.el9_7.aarch64.rpm SHA-256: 473deeb9ae3807e162594daf35ee023a3342cec51f4b6fab0f61491d10a9821f
openssh-debuginfo-8.7p1-47.el9_7.aarch64.rpm SHA-256: 473deeb9ae3807e162594daf35ee023a3342cec51f4b6fab0f61491d10a9821f
openssh-debugsource-8.7p1-47.el9_7.aarch64.rpm SHA-256: abe735cd728071ddd5eccdaa1e89cf8d073108f7f7649284774eba8387d82f72
openssh-debugsource-8.7p1-47.el9_7.aarch64.rpm SHA-256: abe735cd728071ddd5eccdaa1e89cf8d073108f7f7649284774eba8387d82f72
openssh-keycat-8.7p1-47.el9_7.aarch64.rpm SHA-256: a8462118a50cd8a99c491aecfbfe9e99af76865188c619f50f06717d213900ad
openssh-keycat-debuginfo-8.7p1-47.el9_7.aarch64.rpm SHA-256: d536b9020ef51807d977d75f2df0af28d2229b1cb05a8e19a50435385ea091c3
openssh-keycat-debuginfo-8.7p1-47.el9_7.aarch64.rpm SHA-256: d536b9020ef51807d977d75f2df0af28d2229b1cb05a8e19a50435385ea091c3
openssh-server-8.7p1-47.el9_7.aarch64.rpm SHA-256: e6cf85808a397e39a77aa3623d83c5a89375ede0c218d6b4baf17e554382aa51
openssh-server-debuginfo-8.7p1-47.el9_7.aarch64.rpm SHA-256: aa0a59b9c3cbf4fa59505fdf33cf33fc6aeb9031820d7f91da6b7c4e6079631f
openssh-server-debuginfo-8.7p1-47.el9_7.aarch64.rpm SHA-256: aa0a59b9c3cbf4fa59505fdf33cf33fc6aeb9031820d7f91da6b7c4e6079631f
openssh-sk-dummy-debuginfo-8.7p1-47.el9_7.aarch64.rpm SHA-256: 33f5298d8d8d4e899d96ea7beaa05e2a3ea7cfbc2fc7297599f71e19df786c26
openssh-sk-dummy-debuginfo-8.7p1-47.el9_7.aarch64.rpm SHA-256: 33f5298d8d8d4e899d96ea7beaa05e2a3ea7cfbc2fc7297599f71e19df786c26
pam_ssh_agent_auth-0.10.4-5.47.el9_7.aarch64.rpm SHA-256: a882c9181ce510aa7f6f864a76f39cf6df1e2de6be16178c636ee640eab1fb0d
pam_ssh_agent_auth-debuginfo-0.10.4-5.47.el9_7.aarch64.rpm SHA-256: 380be95db0ad525ee21f2deb74a529139319a5a9a2ea3882b50e22e894bc20b0
pam_ssh_agent_auth-debuginfo-0.10.4-5.47.el9_7.aarch64.rpm SHA-256: 380be95db0ad525ee21f2deb74a529139319a5a9a2ea3882b50e22e894bc20b0

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility