Protection mechanism failure in OpenSSH - CVE-2026-60001

 

Protection mechanism failure in OpenSSH - CVE-2026-60001

Published: July 15, 2026


Vulnerability identifier: #VU137703
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-60001
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to weaken authentication rate limiting.

The vulnerability exists due to improper enforcement of security policy in sshd(8) when handling authentication attempts. A remote attacker can send authentication attempts to weaken authentication rate limiting.

The issue affects cases where the minimum authentication delay was not enforced.


Affected software

OpenSSH
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
pam_ssh_agent_auth
openssh
openssh-askpass
openssh-cavs
openssh-clients
openssh-help
openssh-debuginfo
openssh-server
openssh-ldap
openssh-keycat
openssh-debugsource
openssh (Ubuntu package)
openssh-doc
openssh-sk-dummy
openssh-server-config-disallow-rootlogin
openssh-helpers-debuginfo
openssh-common
openssh-fips
openssh-clients-debuginfo
openssh-helpers
openssh-common-debuginfo
openssh-server-debuginfo
openssh-askpass-gnome-debuginfo
openssh-askpass-gnome
openssh-askpass-gnome-debugsource
openssh-cavs-debuginfo

How to mitigate CVE-2026-60001

Install security update from vendor's website.

OpenSSH - update to 10.4p1
pam_ssh_agent_auth - addressed in versions 0.10.3-9.42, 0.10.4-4.48, 0.10.4-5.19, 0.10.4-5.22
openssh - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-askpass - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-cavs - update to 8.2p1-42
openssh-clients - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-help - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-debuginfo - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-server - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-ldap - update to 8.2p1-42
openssh-keycat - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh-debugsource - addressed in versions 8.2p1-42, 8.8p1-48, 9.6p1-19, 9.6p1-22
openssh (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.16, 1:9.6p1-3ubuntu13.18, 1:10.2p1-2ubuntu3.4
openssh-doc - update to 9.6p1-11
openssh-sk-dummy - update to 9.6p1-11
openssh-server - update to 9.6p1-11
openssh-keycat - update to 9.6p1-11
openssh-clients - update to 9.6p1-11
openssh-askpass - update to 9.6p1-11
openssh - update to 9.6p1-11
openssh-server - update to 9.6p1-150600.6.49.1
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.49.1
openssh-helpers-debuginfo - update to 9.6p1-150600.6.49.1
openssh-debugsource - update to 9.6p1-150600.6.49.1
openssh-debuginfo - update to 9.6p1-150600.6.49.1
openssh-common - update to 9.6p1-150600.6.49.1
openssh-fips - update to 9.6p1-150600.6.49.1
openssh-clients-debuginfo - update to 9.6p1-150600.6.49.1
openssh-helpers - update to 9.6p1-150600.6.49.1
openssh-clients - update to 9.6p1-150600.6.49.1
openssh-common-debuginfo - update to 9.6p1-150600.6.49.1
openssh-server-debuginfo - update to 9.6p1-150600.6.49.1
openssh - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debuginfo - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome - update to 9.6p1-150600.6.49.1
openssh-askpass-gnome-debugsource - update to 9.6p1-150600.6.49.1
openssh-cavs - update to 9.6p1-150600.6.49.1
openssh-cavs-debuginfo - update to 9.6p1-150600.6.49.1

External References

Related Security Bulletins