Input validation error in OpenSSH - CVE-2026-35386
Published: April 29, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary shell commands.
The vulnerability exists due to improper input validation in ssh(1) when expanding %-tokens from ssh_config using a user name supplied on the command-line. A local user can supply a specially crafted user name to execute arbitrary shell commands.
Exploitation requires a configuration that uses the %u token in a Match exec block.
Affected software
IBM i
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Ubuntu
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
pam_ssh_agent_auth
openssh (Red Hat package)
openssh-server
openssh-ldap
openssh-keycat
openssh-clients
openssh-cavs
openssh-askpass
openssh
openssh (Ubuntu package)
openssh-help
openssh-debugsource
openssh-debuginfo
How to mitigate CVE-2026-35386
pam_ssh_agent_auth - update to 0.10.3-7.29.0.1
pam_ssh_agent_auth - update to 0.10.4-5.13
openssh (Red Hat package) - addressed in versions 8.0p1-7.el8_4.2, 8.0p1-15.el8_6.5, 8.0p1-20.el8_8.4, 8.0p1-29.el8_10, 8.7p1-30.el9_2.11, 8.7p1-45.el9_6.3, 8.7p1-49.el9_7, 9.9p1-7.el10_0.3, 9.9p1-14.el10_1
openssh-server - update to 8.0p1-29.0.1
openssh-ldap - update to 8.0p1-29.0.1
openssh-keycat - update to 8.0p1-29.0.1
openssh-clients - update to 8.0p1-29.0.1
openssh-cavs - update to 8.0p1-29.0.1
openssh-askpass - update to 8.0p1-29.0.1
openssh - update to 8.0p1-29.0.1
openssh (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.15, 1:9.6p1-3ubuntu13.16, 1:10.0p1-5ubuntu5.4, 1:10.2p1-2ubuntu3.2
openssh-help - update to 9.6p1-13
openssh-server - update to 9.6p1-13
openssh-keycat - update to 9.6p1-13
openssh-debugsource - update to 9.6p1-13
openssh-debuginfo - update to 9.6p1-13
openssh-clients - update to 9.6p1-13
openssh-askpass - update to 9.6p1-13
openssh - update to 9.6p1-13
openssh - addressed in versions 10.0p1-9.fc43, 10.2p1-8.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSH
- Ubuntu update for openssh
- Fedora 43 update for openssh
- Fedora 44 update for openssh
- openEuler update for openssh
- Red Hat Enterprise Linux 10 update for openssh
- Red Hat Enterprise Linux 10 update for openssh
- Red Hat Enterprise Linux 9 update for openssh
- Red Hat Enterprise Linux 8 update for openssh
- Anolis OS update for openssh
- Red Hat Enterprise Linux 9 update for openssh
- Red Hat Enterprise Linux 8 update for openssh
- Red Hat Enterprise Linux 8 update for openssh
- Red Hat Enterprise Linux 8 update for openssh
- Red Hat Enterprise Linux 9 update for openssh
- Multiple vulnerabilities in IBM i