Updated openssh packages fix security vulnerability:
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default
configurations are used, allows privilege escalation because supplemental
groups are not initialized as expected. Helper programs for
AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with
privileges associated with group memberships of the sshd process, if the
configuration specifies running the command as a different user
(CVE-2021-41617).
- https://bugs.mageia.org/show_bug.cgi?id=29517
- https://www.openwall.com/lists/oss-security/2021/09/26/1
- https://www.cve.org/CVERecord?id=CVE-2021-41617
- 8/core/openssh-8.4p1-2.2.mga8
Get the latest Linux and open source security news straight to your inbox.