--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2026-9f73888869
2026-09-21 00:42:44.028749+00:00
--------------------------------------------------------------------------------

Name        : opkssh
Product     : Fedora EPEL 10.3
Version     : 0.16.0
Release     : 3.el10_3
URL         : https://github.com/openpubkey/opkssh
Summary     : OpenPubkey SSH
Description :
OpenPubkey SSH is a tool which enables ssh to be used with OpenID Connect
allowing SSH access to be managed via identities like [email protected] instead
of long-lived SSH keys.

--------------------------------------------------------------------------------
Update Information:

Update the bundled golang.org/x/crypto to v0.56.0, which fixes
CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel
messages in golang.org/x/crypto/ssh's connection multiplexer).
opkssh only uses golang.org/x/crypto/ssh for key and certificate handling
and never establishes SSH connections through it, so the vulnerable code is
not reachable in any opkssh build (confirmed with govulncheck).
--------------------------------------------------------------------------------
ChangeLog:

* Sat Sep 12 2026 Till Hofmann <[email protected]> - 0.16.0-3
- Update bundled golang.org/x/crypto to 0.56.0
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2530690 - CVE-2026-56855 opkssh: golang.org/x/crypto/ssh: Denial 
of Service via crafted messages [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2530690
  [ 2 ] Bug #2530847 - CVE-2026-78662 opkssh: golang.org/x/crypto/ssh: Denial 
of Service via channel request flooding [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2530847
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update opkssh' at the command line.
For more information, refer to "YUM", available at
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\
/html/System_Administrators_Guide/ch-yum.html

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
epel-package-announce mailing list -- 
[email protected]
To unsubscribe send an email to 
[email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to