Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 592
Alerts This Week
Warning Icon 1 592

Fedora 43 opkssh Low GQ-commitment PK Tokens Advisory 2026-168280f3c4

fedora
Calendar Grey July 27, 2026
Scroller Fedora
A minor security fix in opkssh 0.16.0 addresses GitLab-CI GQ-commitment PK Tokens vulnerability for Fedora.
Fedora has released an update for opkssh version 0.16.0, fixing a security vulnerability in GQ-commitment PK Tokens, while updating dependencies and maintaining low severity due to...

Summary

OpenPubkey SSH is a tool which enables ssh to be used with OpenID Connect

allowing SSH access to be managed via identities like alice@example.com instead

of long-lived SSH keys.

Update Information:

Update to 0.16.0. This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.

Change Log

* Sun Jul 19 2026 Till Hofmann - 0.16.0-1 - Update to 0.16.0

References


[ 1 ] Bug #2500487 - opkssh-0.16.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2500487

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-168280f3c4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
low
Lowest
Low
Medium
High
Critical

Name: opkssh
Product: Fedora 43
Version: 0.16.0
Release: 1.fc43
Summary: OpenPubkey SSH

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.