Views
14

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

USN-8721-1 updates OpenSSH for Ubuntu Server 24.04 LTS (noble) to address three security issues in ssh-agent, ssh client forwarding, and sshd tunnel forwarding. The affected packages are openssh-client 1:9.6p1-3ubuntu13.19 and openssh-server 1:9.6p1-3ubuntu13.19. Reference IDs: CVE-2026-73281, CVE-2026-73282, CVE-2026-73283.

Update Details

Security

  • Fixes CVE-2026-73281 in ssh-agent, where agent locking and session-bind@openssh.com interactions could let a remote attacker perform local-only operations through a forwarded agent connection.
  • Fixes CVE-2026-73282 in the OpenSSH client, where concurrent remote-forwarding operations could cause a use-after-free leading to denial of service or arbitrary code execution.
  • Fixes CVE-2026-73283 in sshd, where the restrict keyword from authorized_keys could be bypassed for tunnel forwarding requests.

Hints

  • After a standard system update, restart OpenSSH to apply the fixes.
  • For Ubuntu Server 24.04 LTS (noble), update to openssh-client 1:9.6p1-3ubuntu13.19 and openssh-server 1:9.6p1-3ubuntu13.19.

Product Information

Vendor: Canonical

Product: Ubuntu Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 24.04 LTS (Noble Numbat)

Version: 1:9.6p1-3ubuntu13.19

Vendor release date: Sep 3, 2026

Original release notes: View on vendor site

Published on updatealert.io: Sep 6, 2026

Description: Server operating system for Linux infrastructure and workloads.