Guidance Needed on OpenSSH Vulnerabilities for Oracle Linux 7.9 and 8.10
Hello everyone,
I'm seeking some advice on handling multiple OpenSSH vulnerabilities on Oracle Linux. The advisories recommend upgrading to OpenSSH version 8.4 or 9.6. However, I noticed that no updated packages are currently available in the Oracle Linux repository.
Additionally, I’ve checked advisories from other vendors, and some suggest that these vulnerabilities can be ignored, but I haven't found any specific documentation from Oracle regarding this matter.
The CVE numbers in question are:
- **CVE-2016-20012**
- **CVE-2019-16905**
- **CVE-2021-36368**
- **CVE-2023-51767**
Can anyone provide guidance on whether these vulnerabilities can be safely ignored, or if there’s any alternative solution until the updated packages are available?