{"id":"ECHO-f8b1-1c2f-484d","summary":"QNX 6 / SCO OpenServer 5 only. sshd-session can keep root privileges on\nplatforms that lack file-descriptor passing and need root for PTY\nallocation, via GatewayPorts and StreamLocalForwarding. Linux supports\nfile-descriptor passing, so this code path is not used in Echo's build.\nOpenSSH 10.6 also forcibly disables those options on the affected\nplatforms.\nhttps://www.openssh.com/releasenotes.html#10.6\nhttps://security-tracker.debian.org/tracker/CVE-2026-106589\n","modified":"2026-10-07T15:45:04.831285408Z","published":"2026-10-07T14:12:31.496Z","withdrawn":"2026-10-07T15:00:06.170Z","upstream":["CVE-2026-106589"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-106589"},{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-106589"}],"affected":[{"package":{"name":"openssh","ecosystem":"Echo","purl":"pkg:deb/echo/openssh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:10.6p1-1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-f8b1-1c2f-484d.json"}}],"schema_version":"1.9.0"}