This update for openssh fixes the following issues
Security fixes:
- CVE-2026-3497: information disclosure or denial of service due to uninitialized variables (bsc#1259642).
- CVE-2026-35388: omitted connection multiplexing confirmation for proxy-mode multiplexing sessions (bsc#1261441).
- openssh potential security issue when validating mac or ciphers (bsc#1264568).
Other fixes:
- Improve %prep LDAP regex to preserve subdirectories (e.g., openbsd-compat/) and handle optional [ab]/ prefixes.
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1057=1
- openSUSE Leap 16.0:
openssh-10.0p2-160000.6.1
openssh-askpass-gnome-10.0p2-160000.6.1
openssh-cavs-10.0p2-160000.6.1
openssh-clients-10.0p2-160000.6.1
openssh-common-10.0p2-160000.6.1
openssh-helpers-10.0p2-160000.6.1
openssh-server-10.0p2-160000.6.1
openssh-server-config-rootlogin-10.0p2-160000.6.1
* bsc#1259642
* bsc#1261441
* bsc#1264568
References:
* https://www.suse.com/security/cve/CVE-2026-3497.html
* https://www.suse.com/security/cve/CVE-2026-35388.html
Get the latest Linux and open source security news straight to your inbox.