{"id":"MGASA-2026-0059","summary":"Updated openssh packages fix security vulnerabilities","details":"ssh in OpenSSH before 10.1 allows control characters in usernames that\noriginate from certain possibly untrusted sources, potentially leading\nto code execution when a ProxyCommand is used. The untrusted sources are\nthe command line and %-sequence expansion of a configuration file.\n(CVE-2025-61984)\nssh in OpenSSH before 10.1 allows the '\\0' character in an ssh:// URI,\npotentially leading to code execution when a ProxyCommand is used.\n(CVE-2025-61985)\n","modified":"2026-04-16T04:41:55.213412690Z","published":"2026-03-19T18:04:37Z","upstream":["CVE-2025-61984","CVE-2025-61985"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0059.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35202"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8090-1"}],"affected":[{"package":{"name":"openssh","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/openssh?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.3p1-2.6.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0059.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}