This bug was fixed in the package openssh - 1:10.3p1-4ubuntu1
---------------
openssh (1:10.3p1-4ubuntu1) stonking; urgency=medium
* Merge with Debian unstable. (LP: #2155170)
- Remaining changes:
- debian/rules: modify dh_installsystemd invocations for
socket-activated sshd
- debian/README.Debian: document systemd socket activation.
- debian/.gitignore: drop file
- debian/openssh-server.ucf-md5sum: update for Ubuntu delta
- d/p/systemd-socket-activation.patch:
+ Fix sshd re-execution behavior when socket activation is used
+ Adapt sshd-session and sshd-auth for systemd socket activation
+ Allow AF_VSOCK sockets
- debian/tests/systemd-socket-activation: Add autopkgtest for systemd
socket activation functionality.
- debian/patches: Immediately report interactive instructions to PAM
clients
- debian/control: Build-Depends: systemd-dev
- d/p/sshd-socket-generator.patch: add generator for socket activation
- debian/openssh-server.install: install sshd-socket-generator
- debian/openssh-server.postinst: restart whichever systemd unit is
enabled
- d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator
- ssh.socket: adjust unit for socket activation by default
- debian/rules: explicitly enable LTO
- d/t/ssh-gssapi: disable -e in cleanup()
- d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some
tests
- d/openssh-server.links: add full sshd.service -> ssh.service alias
(LP #2087949)
- document /etc/ssh/sshd_config.d/*.conf better in sshd_config
(LP #2088207)
- d/rules,d/control: do not build with wtmpdb support
- d/t/control: add breaks-testbed restriction to tests
- d/tests: do not fail when $HOME/.ssh exists
- test: workaround test failure caused by uutils dd (LP #2125943)
- Dropped changes:
- d/p/gss-api-defaults.patch: Do not default to weak GSS-API exchange
algorithms.
+ [ Fixed in 1:10.2p1-6 ]
- d/p/sshconnect2-Write-kbd-interactive-service-info-and-instru.patch:
Write kbd-interactive service info and instructions as utf-8.
+ [ Fixed upstream in OpenSSH 10.3p1. ]
- d/p/auth-pam-Add-an-enum-to-define-the-PAM-done-status.patch:
Add an enum to define the PAM done status.
+ [ Fixed upstream in OpenSSH 10.3p1 (SshPamDone enum) ]
- d/p/auth-pam-Add-debugging-information-when-we-receive-PAM-me.patch:
Add debugging information when we receive PAM messages.
+ [ Fixed upstream in OpenSSH 10.3p1. ]
- d/p/auth-pam-Immediately-report-interactive-instructions-to-c.patch:
Immediately report interactive instructions to clients.
+ [ Fixed upstream in OpenSSH 10.3p1. ]
- d/p/CVE-2026-35385.patch, CVE-2026-35386-pre1.patch,
CVE-2026-35386.patch, CVE-2026-35386-2.patch,
CVE-2026-35387_35414.patch, CVE-2026-35388.patch:
Security fixes for CVE-2026-35385, CVE-2026-35386,
CVE-2026-35387, CVE-2026-35388, CVE-2026-35414.
+ [ All fixed upstream in OpenSSH 10.3p1. ]
-- Grayson Wolf <[email protected]> Mon, 08 Jun 2026 09:58:34
-0400
** Changed in: openssh (Ubuntu)
Status: In Progress => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-35385
** CVE added: https://cve.org/CVERecord?id=CVE-2026-35386
** CVE added: https://cve.org/CVERecord?id=CVE-2026-35387
** CVE added: https://cve.org/CVERecord?id=CVE-2026-35388
** CVE added: https://cve.org/CVERecord?id=CVE-2026-35414
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2155170
Title:
Merge openssh from Debian for stonking cycle
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/2155170/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs