Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

openSUSE Leap 16.0: OpenSSH Moderate Code Execution Threat 2025-20122-1

opensuse
Calendar Grey December 1, 2025
Scroller Opensuse
Solve two moderate security issues in OpenSSH on openSUSE Leap 16.0 with this security advisory and patch instructions.
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.

Description

This update for openssh fixes the following issues:

- CVE-2025-61984: code execution via control characters in usernames when a ProxyCommand is used (bsc#1251198).

- CVE-2025-61985: code execution via '\0' character in ssh:// URI when a ProxyCommand is used (bsc#1251199).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-81=1

Patch

Package List

- openSUSE Leap 16.0:

openssh-10.0p2-160000.3.1

openssh-askpass-gnome-10.0p2-160000.3.1

openssh-cavs-10.0p2-160000.3.1

openssh-clients-10.0p2-160000.3.1

openssh-common-10.0p2-160000.3.1

openssh-helpers-10.0p2-160000.3.1

openssh-server-10.0p2-160000.3.1

openssh-server-config-rootlogin-10.0p2-160000.3.1

References

* bsc#1251198

* bsc#1251199

References:

* https://www.suse.com/security/cve/CVE-2025-61984.html

* https://www.suse.com/security/cve/CVE-2025-61985.html

Announcement ID: openSUSE-SU-2025-20122-1
Rating: moderate
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.