SUSE-CU-2026:5970-1: Security update of suse/manager/4.3/proxy-ssh

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sun Jun 14 07:41:59 UTC 2026


SUSE Container Update Advisory: suse/manager/4.3/proxy-ssh
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:5970-1
Container Tags        : suse/manager/4.3/proxy-ssh:4.3.18 , suse/manager/4.3/proxy-ssh:4.3.18.9.69.5 , suse/manager/4.3/proxy-ssh:latest
Container Release     : 9.69.5
Severity              : important
Type                  : security
References            : 1259642 1261427 1261430 1261441 1264568 CVE-2026-3497 CVE-2026-35385
                        CVE-2026-35388 CVE-2026-35414 
-----------------------------------------------------------------

The container suse/manager/4.3/proxy-ssh was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2375-1
Released:    Thu Jun 11 18:05:37 2026
Summary:     Security update for openssh
Type:        security
Severity:    important
References:  1259642,1261427,1261430,1261441,1264568,CVE-2026-3497,CVE-2026-35385,CVE-2026-35388,CVE-2026-35414
This update for openssh fixes the following issues

- CVE-2026-3497: information disclosure or denial of service due to uninitialized variables (bsc#1259642).
- CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427).
- CVE-2026-35388: omitted connection multiplexing confirmation for proxy-mode multiplexing sessions (bsc#1261441).
- CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430).
- potential security issue when validating mac (bsc#1264568).


The following package changes have been done:

- openssh-common-8.4p1-150300.3.65.1 updated
- openssh-fips-8.4p1-150300.3.65.1 updated
- openssh-server-8.4p1-150300.3.65.1 updated
- openssh-clients-8.4p1-150300.3.65.1 updated
- openssh-8.4p1-150300.3.65.1 updated


More information about the sle-container-updates mailing list