Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

openSUSE Leap 16.0: OpenSSH Moderate Code Execution Threat 2025-20122-1

opensuse
Calendar Grey December 1, 2025
Dist Opensuse Esm H88
Solve two moderate security issues in OpenSSH on openSUSE Leap 16.0 with this security advisory and patch instructions.
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.

Description

This update for openssh fixes the following issues:

- CVE-2025-61984: code execution via control characters in usernames when a ProxyCommand is used (bsc#1251198).

- CVE-2025-61985: code execution via '\0' character in ssh:// URI when a ProxyCommand is used (bsc#1251199).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-81=1

Patch

Package List

- openSUSE Leap 16.0:

openssh-10.0p2-160000.3.1

openssh-askpass-gnome-10.0p2-160000.3.1

openssh-cavs-10.0p2-160000.3.1

openssh-clients-10.0p2-160000.3.1

openssh-common-10.0p2-160000.3.1

openssh-helpers-10.0p2-160000.3.1

openssh-server-10.0p2-160000.3.1

openssh-server-config-rootlogin-10.0p2-160000.3.1

References

* bsc#1251198

* bsc#1251199

References:

* https://www.suse.com/security/cve/CVE-2025-61984.html

* https://www.suse.com/security/cve/CVE-2025-61985.html

Announcement ID: openSUSE-SU-2025-20122-1
Rating: moderate
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here