ELSA-2025-23479

ELSA-2025-23479 - openssh security update

Type:SECURITY
Impact:MODERATE
Release Date:2025-12-17

Description


[9.9p1-12.0.1]
- Upstream references found with /usr/bin/ssh [Orabug: 37824421]

[9.9p1-12]
- CVE-2025-61984: Reject usernames with control characters
Resolves: RHEL-128397
- CVE-2025-61985: Reject URL-strings with NULL characters
Resolves: RHEL-128387


Related CVEs


CVE-2025-61984
CVE-2025-61985

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) openssh-9.9p1-12.0.1.el10_1.src.rpm413f953f87ca364894f18fa1446d37c1723b651605c27931ca2af783dfc5b20b-ol10_aarch64_appstream
openssh-9.9p1-12.0.1.el10_1.src.rpm413f953f87ca364894f18fa1446d37c1723b651605c27931ca2af783dfc5b20b-ol10_aarch64_baseos_latest
openssh-9.9p1-12.0.1.el10_1.src.rpm413f953f87ca364894f18fa1446d37c1723b651605c27931ca2af783dfc5b20b-ol10_aarch64_u1_baseos_patch
openssh-9.9p1-12.0.1.el10_1.aarch64.rpm1e91b6113bb57fbcb4c888c21e7af5e6d80d9847591f91821f34d521f6638633-ol10_aarch64_baseos_latest
openssh-9.9p1-12.0.1.el10_1.aarch64.rpm1e91b6113bb57fbcb4c888c21e7af5e6d80d9847591f91821f34d521f6638633-ol10_aarch64_u1_baseos_patch
openssh-askpass-9.9p1-12.0.1.el10_1.aarch64.rpme1c85193c17aa357a28b1979834c2e0b605674b0c3e4fbce38655543a35bca1f-ol10_aarch64_appstream
openssh-clients-9.9p1-12.0.1.el10_1.aarch64.rpm25e20184045d68ea310b177a91af219c5b484a33db4de6819943317b132603a8-ol10_aarch64_baseos_latest
openssh-clients-9.9p1-12.0.1.el10_1.aarch64.rpm25e20184045d68ea310b177a91af219c5b484a33db4de6819943317b132603a8-ol10_aarch64_u1_baseos_patch
openssh-keycat-9.9p1-12.0.1.el10_1.aarch64.rpmb79c747109bc5cfb0f1065cc9eb327539071065cec8f5a53f4a1f8f8731d70e5-ol10_aarch64_baseos_latest
openssh-keycat-9.9p1-12.0.1.el10_1.aarch64.rpmb79c747109bc5cfb0f1065cc9eb327539071065cec8f5a53f4a1f8f8731d70e5-ol10_aarch64_u1_baseos_patch
openssh-keysign-9.9p1-12.0.1.el10_1.aarch64.rpm1922696f37f96a1d2083bf5a7fee2397995c36e9828a3a2c97a5fb7bbfc8bf07-ol10_aarch64_appstream
openssh-server-9.9p1-12.0.1.el10_1.aarch64.rpme216cf1e54d32147eb88c11dd43102e8319b00fb9a1d972575e5c28a588ff372-ol10_aarch64_baseos_latest
openssh-server-9.9p1-12.0.1.el10_1.aarch64.rpme216cf1e54d32147eb88c11dd43102e8319b00fb9a1d972575e5c28a588ff372-ol10_aarch64_u1_baseos_patch
Oracle Linux 10 (x86_64) openssh-9.9p1-12.0.1.el10_1.src.rpm413f953f87ca364894f18fa1446d37c1723b651605c27931ca2af783dfc5b20b-ol10_x86_64_appstream
openssh-9.9p1-12.0.1.el10_1.src.rpm413f953f87ca364894f18fa1446d37c1723b651605c27931ca2af783dfc5b20b-ol10_x86_64_baseos_latest
openssh-9.9p1-12.0.1.el10_1.src.rpm413f953f87ca364894f18fa1446d37c1723b651605c27931ca2af783dfc5b20b-ol10_x86_64_u1_baseos_patch
openssh-9.9p1-12.0.1.el10_1.x86_64.rpmf6c42c226f12e096ce70512169275d708e84721edbd38b30ece05bad30f23b7d-ol10_x86_64_baseos_latest
openssh-9.9p1-12.0.1.el10_1.x86_64.rpmf6c42c226f12e096ce70512169275d708e84721edbd38b30ece05bad30f23b7d-ol10_x86_64_u1_baseos_patch
openssh-askpass-9.9p1-12.0.1.el10_1.x86_64.rpmec149744eada72e55826ca09f993616628f950ade13fd8103004666986e67cc2-ol10_x86_64_appstream
openssh-clients-9.9p1-12.0.1.el10_1.x86_64.rpm9f21d140807b3a3550f847cea7140e3d5fd469bd15c89b313882f353ddb41263-ol10_x86_64_baseos_latest
openssh-clients-9.9p1-12.0.1.el10_1.x86_64.rpm9f21d140807b3a3550f847cea7140e3d5fd469bd15c89b313882f353ddb41263-ol10_x86_64_u1_baseos_patch
openssh-keycat-9.9p1-12.0.1.el10_1.x86_64.rpm79f581ff3b818caaed19134b546ea4ee349b65935f806ec396e7954798ffd9a0-ol10_x86_64_baseos_latest
openssh-keycat-9.9p1-12.0.1.el10_1.x86_64.rpm79f581ff3b818caaed19134b546ea4ee349b65935f806ec396e7954798ffd9a0-ol10_x86_64_u1_baseos_patch
openssh-keysign-9.9p1-12.0.1.el10_1.x86_64.rpmb0fe05af96c01dbd33f34d27236c2e134d43b9a26522fd0b324202ec4f560539-ol10_x86_64_appstream
openssh-server-9.9p1-12.0.1.el10_1.x86_64.rpm2218b2fac06c37e233e65bf6a4a71fad2f67f181b21427f1e56ecb65362e91da-ol10_x86_64_baseos_latest
openssh-server-9.9p1-12.0.1.el10_1.x86_64.rpm2218b2fac06c37e233e65bf6a4a71fad2f67f181b21427f1e56ecb65362e91da-ol10_x86_64_u1_baseos_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete