sslh could be made to overwrite files.. ========================================================================== Ubuntu Security Notice USN-8360-1 June 01, 2026 sslh vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: sslh could be made to overwrite files. Software Description: - sslh: Applicative protocol multiplexer Details: It was discovered that sslh did not properly handle symbolic links when writing its PID file. A local attacker could possibly use this issue to overwrite arbitrary files. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS sslh 2.1.4-1ubuntu0.26.04.1 Ubuntu 25.10 sslh 2.1.4-1ubuntu0.25.10.1 Ubuntu 24.04 LTS sslh 1.22c-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS sslh 1.20-1+deb11u1build0.22.04.1 Ubuntu 20.04 LTS sslh 1.20-1+deb11u1build0.20.04.1 Available with Ubuntu Pro Ubuntu 18.04 LTS sslh 1.18-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS sslh 1.17-2ubuntu0.1~esm1 Available with Ubuntu Pro After a standard system update you need to restart sslh to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8360-1 CVE-2025-52936 Package Information: https://launchpad.net/ubuntu/+source/sslh/2.1.4-1ubuntu0.26.04.1 https://launchpad.net/ubuntu/+source/sslh/2.1.4-1ubuntu0.25.10.1 https://launchpad.net/ubuntu/+source/sslh/1.20-1+deb11u1build0.22.04.1 . Asevere issue in sslh allows local attackers to overwrite files in multiple Ubuntu LTS versions. Update now!. Ubuntu Security, File Overwrite, sslh Issue, LTS Vulnerability, Local Attacks. . Severity: Important. LinuxSecurity.com Team
It was discovered that there was a so-called "link following" vulnerability in sslh, a protocol multiplexor often used to share SSH and HTTPS on the same port. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4238-1
An update that solves 2 vulnerabilities can now be installed.. # sslh-2.2.4-1.1 on GA media Announcement ID: openSUSE-SU-2025:15194-1 Rating: moderate Cross-References: * CVE-2025-46806 * CVE-2025-46807 Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the sslh-2.2.4-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * sslh 2.2.4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-46806.html * https://www.suse.com/security/cve/CVE-2025-46807.html . Corrections for a pair of security vulnerabilities in sslh for openSUSE Tumbleweed provide vital enhancements for users.. openSUSE Tumbleweed, sslh 2.2.4, security updates, open source security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.