ALAS2023-2026-2031


Amazon Linux 2023 Security Advisory: ALAS2023-2026-2031
Advisory Released Date: 2026-08-04
Advisory Updated Date: 2026-08-04
Severity: Medium

Issue Overview:

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS). (CVE-2026-55653)

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session. (CVE-2026-55655)

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. (CVE-2026-59996)

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) (CVE-2026-60002)


Affected Packages:

openssh


Issue Correction:
Run dnf update openssh --releasever 2023.12.20260803 or dnf update --advisory ALAS2023-2026-2031 --releasever 2023.12.20260803 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    openssh-sk-dummy-debuginfo-9.9p1-10.amzn2023.0.1.aarch64
    openssh-debuginfo-9.9p1-10.amzn2023.0.1.aarch64
    openssh-debugsource-9.9p1-10.amzn2023.0.1.aarch64
    openssh-keycat-9.9p1-10.amzn2023.0.1.aarch64
    openssh-keycat-debuginfo-9.9p1-10.amzn2023.0.1.aarch64
    openssh-clients-debuginfo-9.9p1-10.amzn2023.0.1.aarch64
    openssh-server-9.9p1-10.amzn2023.0.1.aarch64
    openssh-server-debuginfo-9.9p1-10.amzn2023.0.1.aarch64
    openssh-9.9p1-10.amzn2023.0.1.aarch64
    openssh-sk-dummy-9.9p1-10.amzn2023.0.1.aarch64
    openssh-clients-9.9p1-10.amzn2023.0.1.aarch64
    pam_ssh_agent_auth-0.10.4-9.10.amzn2023.0.1.aarch64
    pam_ssh_agent_auth-debuginfo-0.10.4-9.10.amzn2023.0.1.aarch64

src:
    openssh-9.9p1-10.amzn2023.0.1.src

x86_64:
    openssh-clients-debuginfo-9.9p1-10.amzn2023.0.1.x86_64
    openssh-keycat-debuginfo-9.9p1-10.amzn2023.0.1.x86_64
    openssh-server-debuginfo-9.9p1-10.amzn2023.0.1.x86_64
    openssh-debuginfo-9.9p1-10.amzn2023.0.1.x86_64
    pam_ssh_agent_auth-debuginfo-0.10.4-9.10.amzn2023.0.1.x86_64
    openssh-sk-dummy-debuginfo-9.9p1-10.amzn2023.0.1.x86_64
    openssh-keycat-9.9p1-10.amzn2023.0.1.x86_64
    openssh-clients-9.9p1-10.amzn2023.0.1.x86_64
    pam_ssh_agent_auth-0.10.4-9.10.amzn2023.0.1.x86_64
    openssh-sk-dummy-9.9p1-10.amzn2023.0.1.x86_64
    openssh-debugsource-9.9p1-10.amzn2023.0.1.x86_64
    openssh-server-9.9p1-10.amzn2023.0.1.x86_64
    openssh-9.9p1-10.amzn2023.0.1.x86_64