First published 14 September 2026 (Pre-Notification)
CVSS:3.1: 7.7 (High)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Summary
Security vulnerabilities have been found in OpenSSH, a secure shell implementation used in IGEL OS. This affects the following product versions:
-
IGEL OS 12
-
IGEL OS 11
Details
It has been discovered that the SSH Client in OpenSSH can have a use-after-free when a server changes its host key during a key re-exchange - this outcome occurs only on the client side. This issue is tracked as CVE-2026-60002 and rated high.
The OpenSSH Server, sshd, does not give the setting DisableForwarding=yes precedence over PermitTunnel=yes as it should (CVE-2026-59999, medium). Apart from that, it does not always honor the minimum authentication delay (CVE-2026-60001, medium).
Update Instructions
-
OS 12: Upgrade the Base System app to version 12.8.3 LTS or 12.10.1 as soon as it is available on the IGEL APP Portal.
-
OS 11: IGEL OS 11 reached End of Maintenance in June 2026. To ensure continued access to security updates and support, we recommend migrating to IGEL OS 12.
References
-
CVE-2026-59999: https://nvd.nist.gov/vuln/detail/cve-2026-59999
-
CVE-2026-60001: https://nvd.nist.gov/vuln/detail/cve-2026-60001
-
CVE-2026-60002: https://nvd.nist.gov/vuln/detail/cve-2026-60002