Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions changelog/security/2026-08-05-openssh-10.4_p1-r1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- openssh ([CVE-2026-59995](https://www.cve.org/CVERecord/?id=CVE-2026-59995), [CVE-2026-59996](https://www.cve.org/CVERecord/?id=CVE-2026-59996), [CVE-2026-59997](https://www.cve.org/CVERecord/?id=CVE-2026-59997), [CVE-2026-59998](https://www.cve.org/CVERecord/?id=CVE-2026-59998), [CVE-2026-59999](https://www.cve.org/CVERecord/?id=CVE-2026-59999), [CVE-2026-60000](https://www.cve.org/CVERecord/?id=CVE-2026-60000), [CVE-2026-60001](https://www.cve.org/CVERecord/?id=CVE-2026-60001), [CVE-2026-60002](https://www.cve.org/CVERecord/?id=CVE-2026-60002))
1 change: 1 addition & 0 deletions changelog/updates/2026-08-05-openssh-10.4_p1-r1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- openssh ([10.4_p1](https://www.openssh.com/txt/release-10.4))
Original file line number Diff line number Diff line change
Expand Up @@ -115,6 +115,9 @@ dev-db/etcd amd64
=net-libs/ngtcp2-1.22.1
=net-misc/curl-8.21.0

# For CVE-2026-{59995,59996,59997,59998,59999,60000,60001,60002}
=net-misc/openssh-10.4_p1-r1

# For podman 6.0.0
=net-misc/passt-2026.05.26

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,8 @@ DIST openssh-10.2p1.tar.gz 1974519 BLAKE2B 8c031b10b1642e21b46f7d1db84ba42692e37
DIST openssh-10.2p1.tar.gz.asc 833 BLAKE2B 34e1a697e9565f5d4e8139537e76e123512285662576f6f2b513ba129d5e42310c1997e70d7c69b2c4fe1c85f9323ef686b8f83f12a73c5a4f229ff855efd7c6 SHA512 f1f71700b1b0b2117aed505488b98b7ebb51ce26e53184b08df0b07aa2c5a1e54dc4d3cbcbe871b5ad849a2a0e22b02af318ff22a68c980ab53b04be03c9bf3c
DIST openssh-10.3p1.tar.gz 2007369 BLAKE2B 77ff7c3bc943702267d74f6f7cdae44209ab940e42501e8a225761f3c8ab5416f2f0e4e61183e0b4cd79d5a041f4d1600674fcda17d3a2bd172074655cefdcd1 SHA512 cb2bd67086491c25e305879b924c3dfa8236502a60c7f250b2fd17d2d9a79ebfc2e40b2f43e42dcf598cc510996e00cc03df9b8e38f34bc2dc71a3d4ff3788fa
DIST openssh-10.3p1.tar.gz.asc 833 BLAKE2B ce5f811225a59b4724092ef3cb7f7815ed1c57088872489b65fd90cdda9898a2cd6fb965e84cdcad3c0288f38784f3001909400941555fec3d3276c455195326 SHA512 2c8afbe57f6712f159aa3a160b6ffc43f945a98ccd8e151fa6a047ea30b376e5e1cac844a678a7899da80704b3d23feda612ffada1ee003f4c7fb8291f484600
DIST openssh-10.4p1.tar.gz 2321796 BLAKE2B 3051a345fd24333708277a1de781deca9094dd07cc55e613e93715b1266d80d59043bf5cdb2282d02c797cb9446916020e70fbd4c7a2470da7ab98eb612f6b74 SHA512 c49600022a3a3f0f0ba4284072cccbe1088030cd175ea166e08251224712731f97cb1a3f039d19f71714c537ab88b177602be0932bc35a26f3227dc09c43f37c
DIST openssh-10.4p1.tar.gz.asc 833 BLAKE2B 408ccf508e90b0fc66e04b07fe4fce6d1d71752f2a85961b4a6ed7d5157100258bd5a5b7ebf806fe040fe509ee6abc5a103e7ebda7336e7b669241026e48870d SHA512 604b8203088d71bee3a93ea644201f82eb1f049b08cf0b57b9f5dbcb9a9bae206283a30af15182e42e59ea63b8e1c9941c8b981a1d026b6a0f49b11ccd7007c4
DIST openssh-9.8_p1-backports.tar.gz 5879 BLAKE2B 98f2864977f512cb658d129cc89385df25b57fb4ec5ac0cb5e2655ff7f8bffa795194a2177a78339999b0d25c9aea708469b322b9d7c814165e570fb5a66ee9b SHA512 541a629b3ce7d20df29b649478f7a4348bed876045cc2b3c95b6544cce87850cd05c1d405e85ce713fb137b7768402d2b0052a6478b781c30a2567ffebcd4322
DIST openssh-9.8p1.tar.gz 1910393 BLAKE2B 3bf983c4ef5358054ed0104cd51d3e0069fbc2b80d8522d0df644d5508ec1d26a67bf061b1b5698d1cdf0d2cbba16b4cdca12a4ce30da24429094576a075e192 SHA512 95dec2f18e58eb47994f3de4430253e0665e185564b65088ca5f4108870e05feddef8cda8d3c0a4b75f18b98cc2c024df0e27de53b48c1a16da8da483cb8292a
DIST openssh-9.8p1.tar.gz.asc 833 BLAKE2B 5291e8c03ab9a75acb44285cd7fc010f4a33551f142499624165dac708fc05a6d077df81555aa41037b45f6301e4e5db3161a7a23404473f8a233a877fc55cc3 SHA512 4df1f1be2c6ab7f3aebaedd0a773b0e8c8929abb30cd3415873ad55d012cfa113f792e888e5e772dd468c394aeb7e35d62893a514dbc0ab1a03acd79918657f7
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,104 @@
https://bugs.gentoo.org/979335

From 823ad00d14065ab932794be8d0a75a86b6277849 Mon Sep 17 00:00:00 2001
Message-ID: <823ad00d14065ab932794be8d0a75a86b6277849.1784450865.git.sam@gentoo.org>
From: "djm@openbsd.org" <djm@openbsd.org>
Date: Tue, 7 Jul 2026 01:00:22 +0000
Subject: [PATCH] upstream: fix GSSAPI option names, that I somehow screwed up
while

refactoring servconf.c bz3974 patch from Colin Watson

OpenBSD-Commit-ID: be39ad3dbe36d9ecdb86f3811da5dfbdc9bcb1e6
---
servconf.c | 18 +++++++++---------
servconf.h | 18 +++++++++---------
2 files changed, 18 insertions(+), 18 deletions(-)

diff --git a/servconf.c b/servconf.c
index ce388f1dd..9b443bea0 100644
--- a/servconf.c
+++ b/servconf.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: servconf.c,v 1.450 2026/06/29 08:59:31 djm Exp $ */
+/* $OpenBSD: servconf.c,v 1.451 2026/07/07 01:00:22 djm Exp $ */
/*
* Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
* All rights reserved
@@ -1433,19 +1433,19 @@ process_server_config_line_depth(ServerOptions *options, char *line,
#endif /* KRB5 */

#ifdef GSSAPI
- case sGssAuthentication:
+ case sGSSAPIAuthentication:
intptr = &options->gss_authentication;
goto parse_flag;

- case sGssCleanupCreds:
+ case sGSSAPICleanupCredentials:
intptr = &options->gss_cleanup_creds;
goto parse_flag;

- case sGssDelegateCreds:
+ case sGSSAPIDelegateCredentials:
intptr = &options->gss_deleg_creds;
goto parse_flag;

- case sGssStrictAcceptor:
+ case sGSSAPIStrictAcceptorCheck:
intptr = &options->gss_strict_acceptor;
goto parse_flag;
#endif /* GSSAPI */
@@ -4215,10 +4215,10 @@ dump_config(ServerOptions *o)
# endif
#endif
#ifdef GSSAPI
- dump_cfg_fmtint(sGssAuthentication, o->gss_authentication);
- dump_cfg_fmtint(sGssCleanupCreds, o->gss_cleanup_creds);
- dump_cfg_fmtint(sGssDelegateCreds, o->gss_deleg_creds);
- dump_cfg_fmtint(sGssStrictAcceptor, o->gss_strict_acceptor);
+ dump_cfg_fmtint(sGSSAPIAuthentication, o->gss_authentication);
+ dump_cfg_fmtint(sGSSAPICleanupCredentials, o->gss_cleanup_creds);
+ dump_cfg_fmtint(sGSSAPIDelegateCredentials, o->gss_deleg_creds);
+ dump_cfg_fmtint(sGSSAPIStrictAcceptorCheck, o->gss_strict_acceptor);
#endif
dump_cfg_fmtint(sPasswordAuthentication, o->password_authentication);
dump_cfg_fmtint(sKbdInteractiveAuthentication,
diff --git a/servconf.h b/servconf.h
index 9e64e4673..a2345e88a 100644
--- a/servconf.h
+++ b/servconf.h
@@ -1,4 +1,4 @@
-/* $OpenBSD: servconf.h,v 1.177 2026/05/31 11:30:50 djm Exp $ */
+/* $OpenBSD: servconf.h,v 1.179 2026/07/07 01:00:22 djm Exp $ */

/*
* Author: Tatu Ylonen <ylo@cs.hut.fi>
@@ -314,16 +314,16 @@ SSHCONF_UNSUPPORTED_INT(kerberos_get_afs_token, KerberosGetAFSToken, SSHCFG_GLOB

#ifdef GSSAPI
#define SSHD_CONFIG_ENTRIES_GSS \
-SSHCONF_INTFLAG(gss_authentication, GssAuthentication, SSHCFG_ALL, 0, SSHCFG_COPY_MATCH) \
-SSHCONF_INTFLAG(gss_cleanup_creds, GssCleanupCreds, SSHCFG_GLOBAL, 1, SSHCFG_COPY_NONE) \
-SSHCONF_INTFLAG(gss_deleg_creds, GssDelegateCreds, SSHCFG_GLOBAL, 1, SSHCFG_COPY_NONE) \
-SSHCONF_INTFLAG(gss_strict_acceptor, GssStrictAcceptor, SSHCFG_GLOBAL, 1, SSHCFG_COPY_NONE)
+SSHCONF_INTFLAG(gss_authentication, GSSAPIAuthentication, SSHCFG_ALL, 0, SSHCFG_COPY_MATCH) \
+SSHCONF_INTFLAG(gss_cleanup_creds, GSSAPICleanupCredentials, SSHCFG_GLOBAL, 1, SSHCFG_COPY_NONE) \
+SSHCONF_INTFLAG(gss_deleg_creds, GSSAPIDelegateCredentials, SSHCFG_GLOBAL, 1, SSHCFG_COPY_NONE) \
+SSHCONF_INTFLAG(gss_strict_acceptor, GSSAPIStrictAcceptorCheck, SSHCFG_GLOBAL, 1, SSHCFG_COPY_NONE)
#else /* GSSAPI */
#define SSHD_CONFIG_ENTRIES_GSS \
-SSHCONF_UNSUPPORTED_INT(gss_authentication, GssAuthentication, SSHCFG_ALL) \
-SSHCONF_UNSUPPORTED_INT(gss_cleanup_creds, GssCleanupCreds, SSHCFG_GLOBAL) \
-SSHCONF_UNSUPPORTED_INT(gss_deleg_creds, GssDelegateCreds, SSHCFG_GLOBAL) \
-SSHCONF_UNSUPPORTED_INT(gss_strict_acceptor, GssStrictAcceptor, SSHCFG_GLOBAL)
+SSHCONF_UNSUPPORTED_INT(gss_authentication, GSSAPIAuthentication, SSHCFG_ALL) \
+SSHCONF_UNSUPPORTED_INT(gss_cleanup_creds, GSSAPICleanupCredentials, SSHCFG_GLOBAL) \
+SSHCONF_UNSUPPORTED_INT(gss_deleg_creds, GSSAPIDelegateCredentials, SSHCFG_GLOBAL) \
+SSHCONF_UNSUPPORTED_INT(gss_strict_acceptor, GSSAPIStrictAcceptorCheck, SSHCFG_GLOBAL)
#endif /* GSSAPI */

#define SSHD_CONFIG_ENTRIES \
--
2.55.0

Loading