> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> USN-8721-1: OpenSSH vulnerabilities

[SOURCE] Ubuntu Security Notices [DATE: 03/09/2026 12:30] [LANGUAGE: EN]
It was discovered that OpenSSH's ssh-agent incorrectly handled interactions between agent locking and the [email protected] extension. A remote attacker with access to a forwarded agent connection could possibly use this issue to perform operations that should only be available locally, such as adding tokens or using keys. (CVE-2026-73281) It was discovered that OpenSSH's ssh client incorrectly handled concurrent remote-forwarding operations. A remote attacker could possibly use this issue to cause a use-after-free condition, resulting in a denial of service or the execution of arbitrary code. (CVE-2026-73282) It was discovered that OpenSSH's sshd server incorrectly applied the restrict keyword from authorized_keys to tunnel forwarding requests. A local attacker with an authorized key could possibly use this issue to bypass intended tunnel forwarding restrictions. (CVE-2026-73283)
[messages.read_original_source] →