CVE-2026-73281

NameCVE-2026-73281
DescriptionIn ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1144192

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openssh (PTS)bookworm1:9.2p1-2+deb12u10vulnerable
bookworm (security)1:9.2p1-2+deb12u9vulnerable
trixie1:10.0p1-7+deb13u4vulnerable
trixie (security)1:10.0p1-7+deb13u2vulnerable
forky, sid1:10.5p1-1fixed
openssh-gssapi (PTS)forky, sid1:10.5p1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opensshsource(unstable)1:10.5p1-11144192
openssh-gssapisource(unstable)1:10.5p1-1

Notes

[trixie] - openssh <no-dsa> (Minor issue)
[bookworm] - openssh <postponed> (Minor issue)
https://www.openwall.com/lists/oss-security/2026/08/12/1
https://www.openssh.org/releasenotes.html#10.5

Search for package or bug name: Reporting problems