Home / mailingsPDF  

[USN-8514-2] OpenSSH vulnerability

Posted on 16 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8514-2
September 16, 2026

openssh vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 14.04 LTS

Summary:

OpenSSH could be made to overwrite files as the administrator.

Software Description:
- openssh: secure shell (SSH) for secure access to remote machines

Details:

USN-8514-1 fixed a vulnerability in OpenSSH. This update provides
the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS.

Original advisory details:

It was discovered that OpenSSH incorrectly handled file permissions when
downloading files as root using the legacy scp protocol without the
preserve-mode option. An attacker could use this to install setuid or setgid
files on a system, possibly leading to privilege escalation.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
openssh-client 1:8.2p1-4ubuntu0.13+esm2
Available with Ubuntu Pro
openssh-server 1:8.2p1-4ubuntu0.13+esm2
Available with Ubuntu Pro

Ubuntu 18.04 LTS
openssh-client 1:7.6p1-4ubuntu0.7+esm5
Available with Ubuntu Pro
openssh-server 1:7.6p1-4ubuntu0.7+esm5
Available with Ubuntu Pro

Ubuntu 14.04 LTS
openssh-client 1:6.6p1-2ubuntu2.13+esm3
Available with Ubuntu Pro
openssh-server 1:6.6p1-2ubuntu2.13+esm3
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8514-2
https://ubuntu.com/security/notices/USN-8514-1
CVE-2026-35385

--===============7198430342843012204==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP