Linux Operating System (MOSC)

MOSC Banner

Guidance Needed on OpenSSH Vulnerabilities for Oracle Linux 7.9 and 8.10

edited Oct 15, 2024 10:05PM in Linux Operating System (MOSC) 3 commentsAnswered ✓

Hello everyone,

I'm seeking some advice on handling multiple OpenSSH vulnerabilities on Oracle Linux. The advisories recommend upgrading to OpenSSH version 8.4 or 9.6. However, I noticed that no updated packages are currently available in the Oracle Linux repository.

Additionally, I’ve checked advisories from other vendors, and some suggest that these vulnerabilities can be ignored, but I haven't found any specific documentation from Oracle regarding this matter.

The CVE numbers in question are:

- **CVE-2016-20012**

- **CVE-2019-16905**

- **CVE-2021-36368**

- **CVE-2023-51767**

Can anyone provide guidance on whether these vulnerabilities can be safely ignored, or if there’s any alternative solution until the updated packages are available?

Tagged:

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center