ELSA-2025-23481

ELSA-2025-23481 - openssh security update

Type:SECURITY
Impact:MODERATE
Release Date:2025-12-18

Description


[8.0p1-27.0.1]
- Update upstream references [Orabug: 36587718]

[8.0p1-27]
- CVE-2025-61984: Reject usernames with control characters
Resolves: RHEL-128400
- CVE-2025-61985: Reject URL-strings with NULL characters
Resolves: RHEL-128390


Related CVEs


CVE-2025-61984
CVE-2025-61985

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) openssh-8.0p1-27.0.1.el8_10.src.rpmd3ed898d5d0fc686091cc94e0e4307b4d59cb6b669598fc405fded4d60d2ec9e-ol8_aarch64_appstream
openssh-8.0p1-27.0.1.el8_10.src.rpmd3ed898d5d0fc686091cc94e0e4307b4d59cb6b669598fc405fded4d60d2ec9e-ol8_aarch64_baseos_latest
openssh-8.0p1-27.0.1.el8_10.src.rpmd3ed898d5d0fc686091cc94e0e4307b4d59cb6b669598fc405fded4d60d2ec9e-ol8_aarch64_u10_baseos_patch
openssh-8.0p1-27.0.1.el8_10.aarch64.rpm110eb1061073ac86ffefe34364f35b4d86caaa01b2f622b45cbf9bd2ee554c19-ol8_aarch64_baseos_latest
openssh-8.0p1-27.0.1.el8_10.aarch64.rpm110eb1061073ac86ffefe34364f35b4d86caaa01b2f622b45cbf9bd2ee554c19-ol8_aarch64_u10_baseos_patch
openssh-askpass-8.0p1-27.0.1.el8_10.aarch64.rpm271e3b24c52cb6a3ea647cd6e21bcd2e90fc4fa9bcd05dd9ef0d8eebf753ba5f-ol8_aarch64_appstream
openssh-cavs-8.0p1-27.0.1.el8_10.aarch64.rpm8d8eb1c64ee649c6d61e4cc75c2fb391ce9685f2e8c0d84d14174540c4425795-ol8_aarch64_baseos_latest
openssh-cavs-8.0p1-27.0.1.el8_10.aarch64.rpm8d8eb1c64ee649c6d61e4cc75c2fb391ce9685f2e8c0d84d14174540c4425795-ol8_aarch64_u10_baseos_patch
openssh-clients-8.0p1-27.0.1.el8_10.aarch64.rpm20853a176716d446e4429d274bd56169bb62c3c1af73adc0c599caf2056d19e8-ol8_aarch64_baseos_latest
openssh-clients-8.0p1-27.0.1.el8_10.aarch64.rpm20853a176716d446e4429d274bd56169bb62c3c1af73adc0c599caf2056d19e8-ol8_aarch64_u10_baseos_patch
openssh-keycat-8.0p1-27.0.1.el8_10.aarch64.rpm76317f44f10f56aa05321f365c866b5ebdd131a937c8aa87b535e6553709b5a4-ol8_aarch64_baseos_latest
openssh-keycat-8.0p1-27.0.1.el8_10.aarch64.rpm76317f44f10f56aa05321f365c866b5ebdd131a937c8aa87b535e6553709b5a4-ol8_aarch64_u10_baseos_patch
openssh-ldap-8.0p1-27.0.1.el8_10.aarch64.rpm49fc0fa76d20d1b11570ad704ca5073f0a5738f1133de5185ebb3c2a72d737f2-ol8_aarch64_baseos_latest
openssh-ldap-8.0p1-27.0.1.el8_10.aarch64.rpm49fc0fa76d20d1b11570ad704ca5073f0a5738f1133de5185ebb3c2a72d737f2-ol8_aarch64_u10_baseos_patch
openssh-server-8.0p1-27.0.1.el8_10.aarch64.rpma77d18ee143ec15f19c5b6cd6f1adaf237c313e8ca7c4555ceeb65f19116fb6b-ol8_aarch64_baseos_latest
openssh-server-8.0p1-27.0.1.el8_10.aarch64.rpma77d18ee143ec15f19c5b6cd6f1adaf237c313e8ca7c4555ceeb65f19116fb6b-ol8_aarch64_u10_baseos_patch
pam_ssh_agent_auth-0.10.3-7.27.0.1.el8_10.aarch64.rpm6eccac60dda248eebd4eb555394964ff24d31a1cd9286ee177eb3b36370f0a0b-ol8_aarch64_baseos_latest
pam_ssh_agent_auth-0.10.3-7.27.0.1.el8_10.aarch64.rpm6eccac60dda248eebd4eb555394964ff24d31a1cd9286ee177eb3b36370f0a0b-ol8_aarch64_u10_baseos_patch
Oracle Linux 8 (x86_64) openssh-8.0p1-27.0.1.el8_10.src.rpmd3ed898d5d0fc686091cc94e0e4307b4d59cb6b669598fc405fded4d60d2ec9e-ol8_x86_64_appstream
openssh-8.0p1-27.0.1.el8_10.src.rpmd3ed898d5d0fc686091cc94e0e4307b4d59cb6b669598fc405fded4d60d2ec9e-ol8_x86_64_baseos_latest
openssh-8.0p1-27.0.1.el8_10.src.rpmd3ed898d5d0fc686091cc94e0e4307b4d59cb6b669598fc405fded4d60d2ec9e-ol8_x86_64_u10_baseos_patch
openssh-8.0p1-27.0.1.el8_10.x86_64.rpm6f36c63ecd8b610c06636f7abac5ac12229400530c876e7d385f54e9928739f7-ol8_x86_64_baseos_latest
openssh-8.0p1-27.0.1.el8_10.x86_64.rpm6f36c63ecd8b610c06636f7abac5ac12229400530c876e7d385f54e9928739f7-ol8_x86_64_u10_baseos_patch
openssh-askpass-8.0p1-27.0.1.el8_10.x86_64.rpmb8f98ee269a8755abf6af4a36fed6dc00bfd37449f4a9e930a71cdd49eda0db9-ol8_x86_64_appstream
openssh-cavs-8.0p1-27.0.1.el8_10.x86_64.rpm6544465d8dad4548a516f8222a4e853dd84450fcddfb2a4834d3277c256ed124-ol8_x86_64_baseos_latest
openssh-cavs-8.0p1-27.0.1.el8_10.x86_64.rpm6544465d8dad4548a516f8222a4e853dd84450fcddfb2a4834d3277c256ed124-ol8_x86_64_u10_baseos_patch
openssh-clients-8.0p1-27.0.1.el8_10.x86_64.rpmd8aaa78d18881e688f76a17f75fb343345d26f271f826578d4ca0314a08dbe7d-ol8_x86_64_baseos_latest
openssh-clients-8.0p1-27.0.1.el8_10.x86_64.rpmd8aaa78d18881e688f76a17f75fb343345d26f271f826578d4ca0314a08dbe7d-ol8_x86_64_u10_baseos_patch
openssh-keycat-8.0p1-27.0.1.el8_10.x86_64.rpm0617c94c9d81978a87a2c3f7bf35f5d5c35cbe6bcd1f135358e9fb63f3fca1b6-ol8_x86_64_baseos_latest
openssh-keycat-8.0p1-27.0.1.el8_10.x86_64.rpm0617c94c9d81978a87a2c3f7bf35f5d5c35cbe6bcd1f135358e9fb63f3fca1b6-ol8_x86_64_u10_baseos_patch
openssh-ldap-8.0p1-27.0.1.el8_10.x86_64.rpm937099375776e0ab4c6f1f71c11dd90a07eb7326b36ac01b137d5468d570db7d-ol8_x86_64_baseos_latest
openssh-ldap-8.0p1-27.0.1.el8_10.x86_64.rpm937099375776e0ab4c6f1f71c11dd90a07eb7326b36ac01b137d5468d570db7d-ol8_x86_64_u10_baseos_patch
openssh-server-8.0p1-27.0.1.el8_10.x86_64.rpm94efc1be921cc9a93caba57ecbe2e63fe1c449aa9c4ab2673ec8d00d56fb5d78-ol8_x86_64_baseos_latest
openssh-server-8.0p1-27.0.1.el8_10.x86_64.rpm94efc1be921cc9a93caba57ecbe2e63fe1c449aa9c4ab2673ec8d00d56fb5d78-ol8_x86_64_u10_baseos_patch
pam_ssh_agent_auth-0.10.3-7.27.0.1.el8_10.x86_64.rpma8ff378cdcee01ccb6b81818bb1e22a64079f54fe8bdd658a789107211f79c6b-ol8_x86_64_baseos_latest
pam_ssh_agent_auth-0.10.3-7.27.0.1.el8_10.x86_64.rpma8ff378cdcee01ccb6b81818bb1e22a64079f54fe8bdd658a789107211f79c6b-ol8_x86_64_u10_baseos_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete