Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Ubuntu Security

USN-8514-1: OpenSSH vulnerability

A vulnerability (CVE-2026-35385, CVSS 7.5 HIGH) in OpenSSH's legacy scp protocol allows an attacker to install setuid or setgid files during a root-initiated file download without the preserve-mode option, potentially leading to privilege escalation. The vulnerability affects OpenBSD OpenSSH versions prior to 10.3, and the fix is to upgrade to version 10.3.
Read Full Article →

Ubuntu Security Notices USN-8514-1 USN-8514-1: OpenSSH vulnerability Publication date 6 July 2026 Overview OpenSSH could be made to overwrite files as the administrator. Releases 16.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Related notices Packages openssh - secure shell (SSH) for secure access to remote machines Details It was discovered that OpenSSH incorrectly handled file permissions when downloading files as root using the legacy scp protocol without the preserve-mode option. An attacker could use this to install setuid or setgid files on a system, possibly leading to privilege escalation. It was discovered that OpenSSH incorrectly handled file permissions when downloading files as root using the legacy scp protocol without the preserve-mode option. An attacker could use this to install setuid or setgid files on a system, possibly leading to privilege escalation. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 16.04 LTS xenial openssh-client – 1:7.2p2-4ubuntu2.10+esm8 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-35385 CVE-2026-35385 Related notices USN-8222-1 USN-8222-1

Share this article