SB2026100536 - Fedora EPEL 10.3 update for python-asyncssh



SB2026100536 - Fedora EPEL 10.3 update for python-asyncssh

Published: October 5, 2026

Security Bulletin ID SB2026100536
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Path traversal (CVE-ID: CVE-2026-54590)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to authenticate as another user.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in AuthorizedKeysFile %u username substitution when processing SSH authentication requests with crafted usernames. A remote attacker can supply a username beginning with ~ to authenticate as another user.

Exploitation requires %u to be the leading path component and a readable authorized-keys file containing the attacker's key to be reachable in the redirected home directory.


2) Path traversal (CVE-ID: CVE-2026-54591)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to overwrite arbitrary files.

The vulnerability exists due to path traversal in the SCP receive path when processing server-provided filenames during SCP downloads. A remote attacker can send SCP filenames containing traversal sequences to overwrite arbitrary files.

User interaction is required to initiate an SCP download from the malicious server.


Remediation

Install update from vendor's website.