NIXPKGS-2026-0949
GitHub issue
published 2 months, 2 weeks ago
Permalink
CVE-2026-35387
3.1 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
8 packages
- openssh-askpass
- opensshWithKerberos
- perlPackages.NetOpenSSH
- perl5Packages.NetOpenSSH
- lxqt.lxqt-openssh-askpass
- perl538Packages.NetOpenSSH
- perl540Packages.NetOpenSSH
- openssh_gssapi
- @LeSuisse accepted
- @LeSuisse published on GitHub
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of …
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
References
Affected products
OpenSSH
- <10.3
Matching in nixpkgs
pkgs.openssh
Implementation of the SSH protocol
pkgs.opensshTest
Implementation of the SSH protocol
pkgs.openssh_hpn
Implementation of the SSH protocol with high performance networking patches
pkgs.openssh_hpnWithKerberos
Implementation of the SSH protocol with high performance networking patches
Ignored packages (8)
pkgs.openssh_gssapi
Implementation of the SSH protocol with GSSAPI support
pkgs.openssh-askpass
A passphrase dialog for OpenSSH and GTK
pkgs.opensshWithKerberos
Implementation of the SSH protocol
pkgs.perlPackages.NetOpenSSH
Perl SSH client package implemented on top of OpenSSH
pkgs.perl5Packages.NetOpenSSH
Perl SSH client package implemented on top of OpenSSH
pkgs.lxqt.lxqt-openssh-askpass
GUI to query passwords on behalf of SSH agents
pkgs.perl538Packages.NetOpenSSH
None
pkgs.perl540Packages.NetOpenSSH
None
Package maintainers
-
@balsoft Alexander Bantyev <balsoft75@gmail.com>
-
@philiptaron Philip Taron <philip.taron@gmail.com>
-
@dasJ Janne Heß <janne@hess.ooo>
-
@helsinki-Jo Joachim Ernst <joachim.ernst@helsinki-systems.de>
-
@pyrox0 Pyrox <pyrox@pyrox.dev>
-
@numinit Morgan Jones <me+nixpkgs@numin.it>
-
@infinisil Silvan Mosberger <contact@infinisil.com>
-
@wahjava Ashish SHUKLA <ashish.is@lostca.se>