Back Linuxsecurity Fedora 43 python-asyncssh Critical Unauthorized Access Fix 2026
import asyncssh 2.23.1 Fix CVE-2026-54590: Unauthorized file modification via authorized-keys directory escape Fix CVE-2026-54591: Arbitrary file write via path traversal in SCP client
* Sat Jul 11 2026 Georg Sauthoff - 2.23.1-1 - import asyncssh 2.23.1 - fix CVE-2026-54590: Unauthorized file modification via authorized-keys directory escape (fixes fedora#2498421, fixes fedora#2498423) - fix CVE-2026-54591: Arbitrary file write via path traversal in SCP client (fixes fedora#2498488)
* Sat Jul 11 2026 Georg Sauthoff - 2.23.1-1 - import asyncssh 2.23.1 - fix CVE-2026-54590: Unauthorized file modification via authorized-keys directory escape (fixes fedora#2498421, fixes fedora#2498423) - fix CVE-2026-54591: Arbitrary file write via path traversal in SCP client (fixes fedora#2498488)
[ 1 ] Bug #2498421 - CVE-2026-54590 python-asyncssh: AsyncSSH: Unauthorized file modification via authorized-keys directory escape [fedora-all] [ 2 ] Bug #2498423 - CVE-2026-54590 python-asyncssh: AsyncSSH: Unauthorized file modification via authorized-keys directory escape [fedora-all] [ 3 ] Bug #2498488 - CVE-2026-54591 python-asyncssh: AsyncSSH: Arbitrary file write via path traversal in SCP client [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-574496d9ae' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
