SB2026100536 - Fedora EPEL 10.3 update for python-asyncssh
Published: October 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Path traversal (CVE-ID: CVE-2026-54590)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to authenticate as another user.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in AuthorizedKeysFile %u username substitution when processing SSH authentication requests with crafted usernames. A remote attacker can supply a username beginning with ~ to authenticate as another user.
Exploitation requires %u to be the leading path component and a readable authorized-keys file containing the attacker's key to be reachable in the redirected home directory.
2) Path traversal (CVE-ID: CVE-2026-54591)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to overwrite arbitrary files.
The vulnerability exists due to path traversal in the SCP receive path when processing server-provided filenames during SCP downloads. A remote attacker can send SCP filenames containing traversal sequences to overwrite arbitrary files.
User interaction is required to initiate an SCP download from the malicious server.
Remediation
Install update from vendor's website.