ISN 2026-37: OpenSSH Vulnerability

First published 14 September 2026 (Pre-Notification)

CVSS:3.1: 7.7 (High)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Summary

Security vulnerabilities have been found in OpenSSH, a secure shell implementation used in IGEL OS. This affects the following product versions:

  • IGEL OS 12

  • IGEL OS 11

Details

It has been discovered that the SSH Client in OpenSSH can have a use-after-free when a server changes its host key during a key re-exchange - this outcome occurs only on the client side. This issue is tracked as CVE-2026-60002 and rated high.

The OpenSSH Server, sshd, does not give the setting DisableForwarding=yes precedence over PermitTunnel=yes as it should (CVE-2026-59999, medium). Apart from that, it does not always honor the minimum authentication delay (CVE-2026-60001, medium).

Update Instructions

  • OS 12: Upgrade the Base System app to version 12.8.3 LTS or 12.10.1 as soon as it is available on the IGEL APP Portal.

  • OS 11: IGEL OS 11 reached End of Maintenance in June 2026. To ensure continued access to security updates and support, we recommend migrating to IGEL OS 12.

References