Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:1790 - Security Advisory
Issued:
2026-02-03
Updated:
2026-02-03

RHSA-2026:1790 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: openssh security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for openssh is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.

Security Fix(es):

  • openssh: potential command injection via shell metacharacters (CVE-2023-51385)
  • openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand (CVE-2025-61984)
  • openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand (CVE-2025-61985)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2255271 - CVE-2023-51385 openssh: potential command injection via shell metacharacters
  • BZ - 2401960 - CVE-2025-61984 openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand
  • BZ - 2401962 - CVE-2025-61985 openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand

CVEs

  • CVE-2023-51385
  • CVE-2025-61984
  • CVE-2025-61985

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
openssh-8.7p1-13.el9_0.1.src.rpm SHA-256: 893ab6cb30d399ac56c519e115f2d58a6d321203db13e6a2d40ff8be928bf199
ppc64le
openssh-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: 3a9241aa901b2b0da16fc7ab00977c285131bde485af2d1f99cde0f3fd35f993
openssh-askpass-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: c43919d44265bbf6a85c0496613a83a3fc7c520d5b5f2e0b7b85e8bc11639f13
openssh-askpass-debuginfo-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: 2dc9e130aea9d894ef9e19bec49bde646e1081e9b6b0fd99ad525271cf317798
openssh-askpass-debuginfo-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: 2dc9e130aea9d894ef9e19bec49bde646e1081e9b6b0fd99ad525271cf317798
openssh-clients-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: c249b1e170d4c817f8d2bdb68e3b8750d627aa373d8247bdded54ca38a6e421d
openssh-clients-debuginfo-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: 95449f07243aadf3c22feb80f0ac16cb0f9db631e46d171df25740c0bb2dac61
openssh-clients-debuginfo-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: 95449f07243aadf3c22feb80f0ac16cb0f9db631e46d171df25740c0bb2dac61
openssh-debuginfo-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: 7bac48c2eb84d80e234482c54e46625b010775fe954292a6f796d909cfd33df0
openssh-debuginfo-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: 7bac48c2eb84d80e234482c54e46625b010775fe954292a6f796d909cfd33df0
openssh-debugsource-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: 74400787893497510b659a9ac89aa75d556f7a23171484e02cb2a7bad926455e
openssh-debugsource-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: 74400787893497510b659a9ac89aa75d556f7a23171484e02cb2a7bad926455e
openssh-keycat-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: 1583ccffba38045cc0a4364b7cf02a4b571a1a4763ba62944374631da8e465c0
openssh-keycat-debuginfo-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: 853e05b83521dba7f66912d673bb7b76873d75081350100b793072a9dad6dcfa
openssh-keycat-debuginfo-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: 853e05b83521dba7f66912d673bb7b76873d75081350100b793072a9dad6dcfa
openssh-server-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: c4936e5bd9b3b178ef12f835c13376cae5c1ac94120131332e3a297ded0e1ab1
openssh-server-debuginfo-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: a07567950215063423f48339193be6ee4ea785e835ced03596e06072fb74e99a
openssh-server-debuginfo-8.7p1-13.el9_0.1.ppc64le.rpm SHA-256: a07567950215063423f48339193be6ee4ea785e835ced03596e06072fb74e99a
pam_ssh_agent_auth-0.10.4-4.13.el9_0.4.ppc64le.rpm SHA-256: 151d7d70975e66930ab1307c4cb606c88decdc6e2677bba4b95409645b936a4a
pam_ssh_agent_auth-debuginfo-0.10.4-4.13.el9_0.4.ppc64le.rpm SHA-256: 15f9982806fed3688f7ec6bacef9748db825f1f15b54aa487a97557cc27b7421
pam_ssh_agent_auth-debuginfo-0.10.4-4.13.el9_0.4.ppc64le.rpm SHA-256: 15f9982806fed3688f7ec6bacef9748db825f1f15b54aa487a97557cc27b7421

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
openssh-8.7p1-13.el9_0.1.src.rpm SHA-256: 893ab6cb30d399ac56c519e115f2d58a6d321203db13e6a2d40ff8be928bf199
x86_64
openssh-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: e1321eef8436f847f8583fe2a725f8af4a46238853b85ec47487c58b573711e4
openssh-askpass-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 2942da41c004d1785d54ae83e95bb453ef7ffbb810450c01ea24ee590844d56c
openssh-askpass-debuginfo-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 65421dd1ca5913c32ff77d9ecb55a9896684ead15d2be0107f7c50ed48112c16
openssh-askpass-debuginfo-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 65421dd1ca5913c32ff77d9ecb55a9896684ead15d2be0107f7c50ed48112c16
openssh-clients-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 54b2e4ca7b935543a29768aa20de2d4e6d9e815ade4a8f1f9d7e36ee15706d32
openssh-clients-debuginfo-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: e720fb743e13dc3a37a7221c1bf1e6472c9cf103e52c9d216186c9e09bf71de6
openssh-clients-debuginfo-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: e720fb743e13dc3a37a7221c1bf1e6472c9cf103e52c9d216186c9e09bf71de6
openssh-debuginfo-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 81e84149db51fbc53eb74ad2443c8893c1abe291925f127b81ea92454fdda558
openssh-debuginfo-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 81e84149db51fbc53eb74ad2443c8893c1abe291925f127b81ea92454fdda558
openssh-debugsource-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 6cd91e595fc37103af9b8201ccf578e86791386a99eba228b722e6ed7d9fe7d5
openssh-debugsource-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 6cd91e595fc37103af9b8201ccf578e86791386a99eba228b722e6ed7d9fe7d5
openssh-keycat-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 861a56466fa900d4ba2acec866e3c03752afcd03533f375da849bdd560665971
openssh-keycat-debuginfo-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 34c50080c4ec6ade97c2c731b5abf670b293e64de03fac446bbc42e6cbf5b0d1
openssh-keycat-debuginfo-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 34c50080c4ec6ade97c2c731b5abf670b293e64de03fac446bbc42e6cbf5b0d1
openssh-server-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: fddc9e522ffef1e11e909290e078cec09fcefd58bcb84a42838f7a4910585303
openssh-server-debuginfo-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 858500b1e6df41bd54406a742d8fb4ad9e486531f872e2acb1937d7942f9e6bc
openssh-server-debuginfo-8.7p1-13.el9_0.1.x86_64.rpm SHA-256: 858500b1e6df41bd54406a742d8fb4ad9e486531f872e2acb1937d7942f9e6bc
pam_ssh_agent_auth-0.10.4-4.13.el9_0.4.x86_64.rpm SHA-256: 344f4b47012c0e9a3389678b50fb27216a022b5516886b05e92ea2ba472d9987
pam_ssh_agent_auth-debuginfo-0.10.4-4.13.el9_0.4.x86_64.rpm SHA-256: 0846ab26487018ec205117e939120670fd97ac546c546ff9194a2cfd2cd7b970
pam_ssh_agent_auth-debuginfo-0.10.4-4.13.el9_0.4.x86_64.rpm SHA-256: 0846ab26487018ec205117e939120670fd97ac546c546ff9194a2cfd2cd7b970

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
openssh-8.7p1-13.el9_0.1.src.rpm SHA-256: 893ab6cb30d399ac56c519e115f2d58a6d321203db13e6a2d40ff8be928bf199
aarch64
openssh-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: 89bf2615e3fb88a5995a1853e92eeb829e641b7452bba9056f7dd85f6255b4e6
openssh-askpass-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: 820bdce26f23aa7a8f8d8053835edad0db9d60b8494278b32c457f9a954e0656
openssh-askpass-debuginfo-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: ba399c66413b3678b48d04797d08e832930ce064ccb36d87a472f44d360efc49
openssh-askpass-debuginfo-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: ba399c66413b3678b48d04797d08e832930ce064ccb36d87a472f44d360efc49
openssh-clients-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: 63e7e2fe8af95595e37196bad7be53f25e4697b439f20391dcc53dbd26fc7778
openssh-clients-debuginfo-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: 5ab00cdad5216c1f335b83e1f87e6cd483afb8414c7a90887f48bb066f618921
openssh-clients-debuginfo-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: 5ab00cdad5216c1f335b83e1f87e6cd483afb8414c7a90887f48bb066f618921
openssh-debuginfo-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: 777a40e1479eaf746c1f09770e886483a54062689e0eaa9688041d2a7bf53ccd
openssh-debuginfo-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: 777a40e1479eaf746c1f09770e886483a54062689e0eaa9688041d2a7bf53ccd
openssh-debugsource-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: c472bb8c629980f006efddf5136161782e6a3aa12f19e4cfec4fa111e9837d3f
openssh-debugsource-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: c472bb8c629980f006efddf5136161782e6a3aa12f19e4cfec4fa111e9837d3f
openssh-keycat-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: d40d0031c89b3370950ab2b2c956e88e76b08711d3652cae3bd8aa7b60533782
openssh-keycat-debuginfo-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: 4db4ec96bd42bfed57456affed24ddf9701144124b4237eec5d4e1f9de591c85
openssh-keycat-debuginfo-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: 4db4ec96bd42bfed57456affed24ddf9701144124b4237eec5d4e1f9de591c85
openssh-server-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: 31679d24bc3c9bb9fe6113405cd715d1585f4ad2a7f417c14e7bfa385ad602b9
openssh-server-debuginfo-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: d31913a2691bc7c2406ded8d8e0c5f15bacb28a777672df842858c927092fca0
openssh-server-debuginfo-8.7p1-13.el9_0.1.aarch64.rpm SHA-256: d31913a2691bc7c2406ded8d8e0c5f15bacb28a777672df842858c927092fca0
pam_ssh_agent_auth-0.10.4-4.13.el9_0.4.aarch64.rpm SHA-256: 9c19572b5709298c1bf3bf04b0feb175933e18d2f1af25f22d8011d4838ee2a8
pam_ssh_agent_auth-debuginfo-0.10.4-4.13.el9_0.4.aarch64.rpm SHA-256: bcaa7bf890d0f1e3437f19134483b25bd243dd09adfcbb90a25491a0088543a6
pam_ssh_agent_auth-debuginfo-0.10.4-4.13.el9_0.4.aarch64.rpm SHA-256: bcaa7bf890d0f1e3437f19134483b25bd243dd09adfcbb90a25491a0088543a6

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
openssh-8.7p1-13.el9_0.1.src.rpm SHA-256: 893ab6cb30d399ac56c519e115f2d58a6d321203db13e6a2d40ff8be928bf199
s390x
openssh-8.7p1-13.el9_0.1.s390x.rpm SHA-256: 2f922cb16fd994f765b673abcc28cc93252e7f210feddff8097d4ab8c61011ca
openssh-askpass-8.7p1-13.el9_0.1.s390x.rpm SHA-256: 86725ddfa229e9b6e9f7cfc84c7a3dad508db0b0047c1d8e2dcc6b89e72c77ed
openssh-askpass-debuginfo-8.7p1-13.el9_0.1.s390x.rpm SHA-256: 59250d97aa4620c45b3d48147e68400ac28f10463b5b78e387b3fd72ff0e7a65
openssh-askpass-debuginfo-8.7p1-13.el9_0.1.s390x.rpm SHA-256: 59250d97aa4620c45b3d48147e68400ac28f10463b5b78e387b3fd72ff0e7a65
openssh-clients-8.7p1-13.el9_0.1.s390x.rpm SHA-256: bec4f7288e0dbbf3f327b170d97c821338d941bf4122a746a89501de3cbf868b
openssh-clients-debuginfo-8.7p1-13.el9_0.1.s390x.rpm SHA-256: b32baa6cb5addac99b219036ed7dd9e5dfb557ff71c347be3eed43db446a5d0d
openssh-clients-debuginfo-8.7p1-13.el9_0.1.s390x.rpm SHA-256: b32baa6cb5addac99b219036ed7dd9e5dfb557ff71c347be3eed43db446a5d0d
openssh-debuginfo-8.7p1-13.el9_0.1.s390x.rpm SHA-256: a66292aa84985ef10cf82a8a37bd5a1668c9c74dbc6020ce8ef88368063cf500
openssh-debuginfo-8.7p1-13.el9_0.1.s390x.rpm SHA-256: a66292aa84985ef10cf82a8a37bd5a1668c9c74dbc6020ce8ef88368063cf500
openssh-debugsource-8.7p1-13.el9_0.1.s390x.rpm SHA-256: 81af156bc1c2f066ea7f91b5d64f7aa781849a84d64d3544ae4bb0067b8fe7e5
openssh-debugsource-8.7p1-13.el9_0.1.s390x.rpm SHA-256: 81af156bc1c2f066ea7f91b5d64f7aa781849a84d64d3544ae4bb0067b8fe7e5
openssh-keycat-8.7p1-13.el9_0.1.s390x.rpm SHA-256: 9c90bf2f21c1953ac21671b4dce01dd5b5185ceee44cf5d2b55c4e3ed0c33327
openssh-keycat-debuginfo-8.7p1-13.el9_0.1.s390x.rpm SHA-256: 66c6363e5a8eaaf7d2cff80f35906992ac142363139bef0d72e1ca8e9b9b8834
openssh-keycat-debuginfo-8.7p1-13.el9_0.1.s390x.rpm SHA-256: 66c6363e5a8eaaf7d2cff80f35906992ac142363139bef0d72e1ca8e9b9b8834
openssh-server-8.7p1-13.el9_0.1.s390x.rpm SHA-256: 25e8c32ab5fa7ae57b6bee89ac0e90157de21ec9ccc6c91b00883444a3f236a6
openssh-server-debuginfo-8.7p1-13.el9_0.1.s390x.rpm SHA-256: 7b10d038e31a994df96c37cde23f8bbc3552b312474954fd977ae06c2907d201
openssh-server-debuginfo-8.7p1-13.el9_0.1.s390x.rpm SHA-256: 7b10d038e31a994df96c37cde23f8bbc3552b312474954fd977ae06c2907d201
pam_ssh_agent_auth-0.10.4-4.13.el9_0.4.s390x.rpm SHA-256: 821c1920cfed4f003f937258f2e8b7357f6625eecef839d11e1228be9b2b8f0e
pam_ssh_agent_auth-debuginfo-0.10.4-4.13.el9_0.4.s390x.rpm SHA-256: 8bac2ab49191e99a71c3b97b5c3f04d2d188451419957648370aa22f1ce9b8e9
pam_ssh_agent_auth-debuginfo-0.10.4-4.13.el9_0.4.s390x.rpm SHA-256: 8bac2ab49191e99a71c3b97b5c3f04d2d188451419957648370aa22f1ce9b8e9

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility