CVE-2026-35385

EUVD-2026-18398
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 46.42%
Affected Products (NVD)
VendorProductVersion
openbsdopenssh
𝑥
< 10.3
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Enterprise Linux 10
0:9.9p1-14.el10_1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10
0:9.9p1-23.el10_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
0:9.9p1-7.el10_0.3 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
0:5.3p1-125.el6_10.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
0:7.4p1-23.el7_9.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
0:8.0p1-29.el8_10 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
0:8.0p1-7.el8_4.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
0:8.0p1-7.el8_4.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
0:8.0p1-15.el8_6.5 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Telecommunications Update Service
0:8.0p1-15.el8_6.5 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Update Services for SAP Solutions
0:8.0p1-15.el8_6.5 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
0:8.0p1-20.el8_8.4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
0:8.0p1-20.el8_8.4 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:8.7p1-49.el9_7 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:9.9p1-7.el9_8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
0:8.7p1-30.el9_2.11 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support
0:8.7p1-38.el9_4.8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
0:8.7p1-45.el9_6.3 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.12
412.86.202606140301-0 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.13
413.92.202606160406-0 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.14
414.92.202606231112-0 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.15
415.92.202606200237-0 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.16
416.94.202606051757-0 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.17
417.94.202606250942-0 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.18
418.94.202606051320-0 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.19
4.19.9.6.202605201155-0 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.2
1780681984 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1782352950 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1782352919 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1782353093 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1782352847 ≤
𝑥
< *
ADP
Red HatRed Hat Discovery 2
1778101579 ≤
𝑥
< *
ADP
Red HatRed Hat Discovery 2
1778156756 ≤
𝑥
< *
ADP
Red HatRed Hat Update Infrastructure 5
1779798165 ≤
𝑥
< *
ADP
Red HatRed Hat Update Infrastructure 5
1779798222 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
openssh
bookworm
1:9.2p1-2+deb12u10
fixed
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
1:8.4p1-5+deb11u7
fixed
forky
1:10.4p1-4
fixed
sid
1:10.4p1-4
fixed
trixie
1:10.0p1-7+deb13u4
fixed
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssh
bionic
needs-triage
focal
needs-triage
jammy
Fixed 1:8.9p1-3ubuntu0.15
released
noble
Fixed 1:9.6p1-3ubuntu13.16
released
questing
Fixed 1:10.0p1-5ubuntu5.4
released
resolute
Fixed 1:10.2p1-2ubuntu3.2
released
trusty
needs-triage
xenial
Fixed 1:7.2p2-4ubuntu2.10+esm8
released
openssh-ssh1
bionic
ignored
focal
ignored
jammy
ignored
noble
ignored
questing
ignored
resolute
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
openssh
RHEL 8
0:8.0p1-29.el8_10
fixed
RHEL 8.4 AUS
0:8.0p1-7.el8_4.2
fixed
RHEL 8.6 AUS
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 E4S
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 TUS
0:8.0p1-15.el8_6.5
fixed
RHEL 8.8 E4S
0:8.0p1-20.el8_8.4
fixed
RHEL 8.8 TUS
0:8.0p1-20.el8_8.4
fixed
RHEL 9
0:9.9p1-7.el9_8
fixed
openssh-askpass
RHEL 8
0:8.0p1-29.el8_10
fixed
RHEL 8.6 AUS
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 E4S
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 TUS
0:8.0p1-15.el8_6.5
fixed
RHEL 9
0:9.9p1-7.el9_8
fixed
openssh-cavs
RHEL 8
0:8.0p1-29.el8_10
fixed
RHEL 8.6 AUS
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 E4S
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 TUS
0:8.0p1-15.el8_6.5
fixed
openssh-clients
RHEL 8
0:8.0p1-29.el8_10
fixed
RHEL 8.4 AUS
0:8.0p1-7.el8_4.2
fixed
RHEL 8.6 AUS
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 E4S
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 TUS
0:8.0p1-15.el8_6.5
fixed
RHEL 8.8 E4S
0:8.0p1-20.el8_8.4
fixed
RHEL 8.8 TUS
0:8.0p1-20.el8_8.4
fixed
RHEL 9
0:9.9p1-7.el9_8
fixed
openssh-keycat
RHEL 8
0:8.0p1-29.el8_10
fixed
RHEL 8.6 AUS
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 E4S
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 TUS
0:8.0p1-15.el8_6.5
fixed
RHEL 9
0:9.9p1-7.el9_8
fixed
openssh-ldap
RHEL 8
0:8.0p1-29.el8_10
fixed
RHEL 8.6 AUS
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 E4S
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 TUS
0:8.0p1-15.el8_6.5
fixed
openssh-server
RHEL 8
0:8.0p1-29.el8_10
fixed
RHEL 8.4 AUS
0:8.0p1-7.el8_4.2
fixed
RHEL 8.6 AUS
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 E4S
0:8.0p1-15.el8_6.5
fixed
RHEL 8.6 TUS
0:8.0p1-15.el8_6.5
fixed
RHEL 8.8 E4S
0:8.0p1-20.el8_8.4
fixed
RHEL 8.8 TUS
0:8.0p1-20.el8_8.4
fixed
RHEL 9
0:9.9p1-7.el9_8
fixed
pam
RHEL 8
0:0.10.3-7.29.el8_10
fixed
RHEL 8.6 AUS
0:0.10.3-7.15.el8_6.5
fixed
RHEL 8.6 E4S
0:0.10.3-7.15.el8_6.5
fixed
RHEL 8.6 TUS
0:0.10.3-7.15.el8_6.5
fixed
RHEL 9
0:0.10.4-7.7.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
openssh
Amazon Linux 2
0:7.4p1-22.amzn2.0.12
fixed
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.17
fixed
openssh-askpass
Amazon Linux 2
0:7.4p1-22.amzn2.0.12
fixed
openssh-cavs
Amazon Linux 2
0:7.4p1-22.amzn2.0.12
fixed
openssh-clients
Amazon Linux 2
0:7.4p1-22.amzn2.0.12
fixed
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.17
fixed
openssh-clients-debuginfo
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.17
fixed
openssh-debuginfo
Amazon Linux 2
0:7.4p1-22.amzn2.0.12
fixed
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.17
fixed
openssh-debugsource
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.17
fixed
openssh-keycat
Amazon Linux 2
0:7.4p1-22.amzn2.0.12
fixed
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.17
fixed
openssh-keycat-debuginfo
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.17
fixed
openssh-ldap
Amazon Linux 2
0:7.4p1-22.amzn2.0.12
fixed
openssh-server
Amazon Linux 2
0:7.4p1-22.amzn2.0.12
fixed
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.17
fixed
openssh-server-debuginfo
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.17
fixed
openssh-server-sysvinit
Amazon Linux 2
0:7.4p1-22.amzn2.0.12
fixed
pam_ssh_agent_auth
Amazon Linux 2
0:0.10.3-2.22.amzn2.0.12
fixed
Amazon Linux 2023
0:0.10.4-4.8.amzn2023.0.17
fixed
pam_ssh_agent_auth-debuginfo
Amazon Linux 2023
0:0.10.4-4.8.amzn2023.0.17
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
openssh
Azure Linux 3.0
0:9.8p1-6.azl3
fixed
References