ELSA-2026-6462

ELSA-2026-6462 - openssh security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-04-03

Description


[8.7p1-48.0.1]
- Upstream references found with /usr/bin/ssh [Orabug: 37814929]
- upstream: fix AuthorizedPrincipalsCommand when AuthorizedKeysCommand [Orabug: 37647064]
- Update upstream references [Orabug: 36564626]

[8.7p1-48]
- CVE-2026-3497: Fix information disclosure or denial of service due
to uninitialized variables in gssapi-keyex
Resolves: RHEL-155823


Related CVEs


CVE-2026-3497

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) openssh-8.7p1-48.0.1.el9_7.src.rpm0d695be1badf6b890158e334151943cb42ad5df14a958461bfdf49ef63c85a52-ol9_aarch64_appstream
openssh-8.7p1-48.0.1.el9_7.src.rpm0d695be1badf6b890158e334151943cb42ad5df14a958461bfdf49ef63c85a52-ol9_aarch64_baseos_latest
openssh-8.7p1-48.0.1.el9_7.src.rpm0d695be1badf6b890158e334151943cb42ad5df14a958461bfdf49ef63c85a52-ol9_aarch64_u7_baseos_patch
openssh-8.7p1-48.0.1.el9_7.aarch64.rpm7bd9f1d5dbd9f49c4df9bc9e952d9991dda6b17cb4c135e53b571b00713c3a61-ol9_aarch64_baseos_latest
openssh-8.7p1-48.0.1.el9_7.aarch64.rpm7bd9f1d5dbd9f49c4df9bc9e952d9991dda6b17cb4c135e53b571b00713c3a61-ol9_aarch64_u7_baseos_patch
openssh-askpass-8.7p1-48.0.1.el9_7.aarch64.rpmc78abefaa4d5e5d7f6d676e777cf949c92d3572e0310ce841ffec90a3c41ed06-ol9_aarch64_appstream
openssh-clients-8.7p1-48.0.1.el9_7.aarch64.rpm2d32c578c7643f9265479c84c92628a9e52a835d91990327b4530fd7676fb3b5-ol9_aarch64_baseos_latest
openssh-clients-8.7p1-48.0.1.el9_7.aarch64.rpm2d32c578c7643f9265479c84c92628a9e52a835d91990327b4530fd7676fb3b5-ol9_aarch64_u7_baseos_patch
openssh-keycat-8.7p1-48.0.1.el9_7.aarch64.rpm268ad82fd3b64862c7baf7a5d1be3073d60c3f2cc5470a166d9783f2615222f9-ol9_aarch64_baseos_latest
openssh-keycat-8.7p1-48.0.1.el9_7.aarch64.rpm268ad82fd3b64862c7baf7a5d1be3073d60c3f2cc5470a166d9783f2615222f9-ol9_aarch64_u7_baseos_patch
openssh-server-8.7p1-48.0.1.el9_7.aarch64.rpm66e023ae22e4b70680b912195f4f4030b776aad2d810c470a964017896b91bfc-ol9_aarch64_baseos_latest
openssh-server-8.7p1-48.0.1.el9_7.aarch64.rpm66e023ae22e4b70680b912195f4f4030b776aad2d810c470a964017896b91bfc-ol9_aarch64_u7_baseos_patch
pam_ssh_agent_auth-0.10.4-5.48.0.1.el9_7.aarch64.rpm9e559205c36a51ab52621bf9ba147c5fb13d396e8f00944dfbf50c768c3a9ce7-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) openssh-8.7p1-48.0.1.el9_7.src.rpm0d695be1badf6b890158e334151943cb42ad5df14a958461bfdf49ef63c85a52-ol9_x86_64_appstream
openssh-8.7p1-48.0.1.el9_7.src.rpm0d695be1badf6b890158e334151943cb42ad5df14a958461bfdf49ef63c85a52-ol9_x86_64_baseos_latest
openssh-8.7p1-48.0.1.el9_7.src.rpm0d695be1badf6b890158e334151943cb42ad5df14a958461bfdf49ef63c85a52-ol9_x86_64_u7_baseos_patch
openssh-8.7p1-48.0.1.el9_7.x86_64.rpmdd8a7df7c4481cb4d31597f9955a5e9107e381e3a226435c9368988fd81c1f83-ol9_x86_64_baseos_latest
openssh-8.7p1-48.0.1.el9_7.x86_64.rpmdd8a7df7c4481cb4d31597f9955a5e9107e381e3a226435c9368988fd81c1f83-ol9_x86_64_u7_baseos_patch
openssh-askpass-8.7p1-48.0.1.el9_7.x86_64.rpm7f96587995d7b397ecede1ed52a1c01645c7999173e7499aeca2080e1f205f1d-ol9_x86_64_appstream
openssh-clients-8.7p1-48.0.1.el9_7.x86_64.rpm302e5498c60b7db7ccca0dd7b680e74bf2d988d8973baa542ffcdfce6897708d-ol9_x86_64_baseos_latest
openssh-clients-8.7p1-48.0.1.el9_7.x86_64.rpm302e5498c60b7db7ccca0dd7b680e74bf2d988d8973baa542ffcdfce6897708d-ol9_x86_64_u7_baseos_patch
openssh-keycat-8.7p1-48.0.1.el9_7.x86_64.rpmd935b7ae415368bc6aba518594b4af08d2a2cc88124fdb5b7eb93a4fa0d74577-ol9_x86_64_baseos_latest
openssh-keycat-8.7p1-48.0.1.el9_7.x86_64.rpmd935b7ae415368bc6aba518594b4af08d2a2cc88124fdb5b7eb93a4fa0d74577-ol9_x86_64_u7_baseos_patch
openssh-server-8.7p1-48.0.1.el9_7.x86_64.rpm8f97dee91b17c83343c7e18777f9eea3feecd79ffb1823590579c0ea3f0d5fda-ol9_x86_64_baseos_latest
openssh-server-8.7p1-48.0.1.el9_7.x86_64.rpm8f97dee91b17c83343c7e18777f9eea3feecd79ffb1823590579c0ea3f0d5fda-ol9_x86_64_u7_baseos_patch
pam_ssh_agent_auth-0.10.4-5.48.0.1.el9_7.x86_64.rpm608fa0986ed55417db2e77b88c725ce4b6d28fb8192181c90f3092b538a04ff6-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete