-------------------------------------------------------------------------------- Fedora EPEL Update Notification FEDORA-EPEL-2026-878ec4ee25 2026-09-21 00:28:29.502178+00:00 --------------------------------------------------------------------------------
Name : opkssh Product : Fedora EPEL 10.2 Version : 0.16.0 Release : 3.el10_2 URL : https://github.com/openpubkey/opkssh Summary : OpenPubkey SSH Description : OpenPubkey SSH is a tool which enables ssh to be used with OpenID Connect allowing SSH access to be managed via identities like [email protected] instead of long-lived SSH keys. -------------------------------------------------------------------------------- Update Information: Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer). opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck). -------------------------------------------------------------------------------- ChangeLog: * Sat Sep 12 2026 Till Hofmann <[email protected]> - 0.16.0-3 - Update bundled golang.org/x/crypto to 0.56.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2530690 - CVE-2026-56855 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2530690 [ 2 ] Bug #2530847 - CVE-2026-78662 opkssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2530847 -------------------------------------------------------------------------------- This update can be installed with the "yum" update programs. Use su -c 'yum update opkssh' at the command line. For more information, refer to "YUM", available at https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\ /html/System_Administrators_Guide/ch-yum.html All packages are signed with the Fedora EPEL GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ epel-package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
