Security News

Cybersecurity news aggregator

🐧
HIGH Vulnerabilities Ubuntu Security

USN-8514-2: OpenSSH vulnerability

A vulnerability (CVE-2026-35385, CVSS 7.5 HIGH) in OpenSSH's legacy scp protocol allows an attacker to overwrite files as root when downloading without the preserve-mode option, potentially installing setuid/setgid files for privilege escalation. The NVD states the vulnerability affects OpenBSD OpenSSH versions prior to 10.3. The fixed version is OpenSSH 10.3.
Read Full Article →

Ubuntu Security Notices USN-8514-2 USN-8514-2: OpenSSH vulnerability Publication date 16 September 2026 Overview OpenSSH could be made to overwrite files as the administrator. Releases 20.04 LTS 18.04 LTS 14.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Related notices Packages openssh - secure shell (SSH) for secure access to remote machines Details USN-8514-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that OpenSSH incorrectly handled file permissions when downloading files as root using the legacy scp protocol without the preserve-mode option. An attacker could use this to install setuid or setgid files on a system, possibly leading to privilege escalation. USN-8514-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that OpenSSH incorrectly handled file permissions when downloading files as root using the legacy scp protocol without the preserve-mode option. An attacker could use this to install setuid or setgid files on a system, possibly leading to privilege escalation. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 20.04 LTS focal openssh-client – 1:8.2p1-4ubuntu0.13+esm2 Ubuntu Pro Fix available with Ubuntu Pro . openssh-server – 1:8.2p1-4ubuntu0.13+esm2 Ubuntu Pro Fix available with Ubuntu Pro . 18.04 LTS bionic openssh-client – 1:7.6p1-4ubuntu0.7+esm5 Ubuntu Pro Fix available with Ubuntu Pro . openssh-server – 1:7.6p1-4ubuntu0.7+esm5 Ubuntu Pro Fix available with Ubuntu Pro . 14.04 LTS trusty openssh-client – 1:6.6p1-2ubuntu2.13+esm3 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. openssh-server – 1:6.6p1-2ubuntu2.13+esm3 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-35385 CVE-2026-35385 Related notices USN-8514-1 USN-8222-1 USN-8514-1 USN-8222-1

Share this article