CVE-2026-73281

NameCVE-2026-73281
DescriptionIn ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1144192

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openssh (PTS)bullseye1:8.4p1-5+deb11u3vulnerable
bullseye (security)1:8.4p1-5+deb11u7vulnerable
bookworm1:9.2p1-2+deb12u10vulnerable
bookworm (security)1:9.2p1-2+deb12u9vulnerable
trixie1:10.0p1-7+deb13u4vulnerable
trixie (security)1:10.0p1-7+deb13u2vulnerable
forky, sid1:10.4p1-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opensshsource(unstable)(unfixed)1144192

Notes

https://www.openwall.com/lists/oss-security/2026/08/12/1
https://www.openssh.org/releasenotes.html#10.5

Search for package or bug name: Reporting problems