Skip to content
Fedora 44 python-asyncssh Important Unauthorized File Write CVE-2026

Fedora 44 python-asyncssh Important Unauthorized File Write CVE-2026

Linuxsecurity LinuxSecurity Advisories July 20, 2026

update to version 2.24.0 Fix CVE-2026-54590: Unauthorized file modification via authorized-keys directory escape Fix CVE-2026-54591: Arbitrary file write via path traversal in SCP client

* Sun Jun 28 2026 Georg Sauthoff - 2.24.0-1 - update to version 2.24.0 (fixes fedora#2468438) * Fri Jun 12 2026 Yaakov Selkowitz - 2.22.0-6 - Rebuilt for openssl 4.0 * Thu Jun 4 2026 Python Maint - 2.22.0-5 - Rebuilt for Python 3.15 * Wed May 6 2026 Miro Hrončok - 2.22.0-4 - Properly filter out test dependency on uvloop and python-pkcs11

* Sun Jun 28 2026 Georg Sauthoff - 2.24.0-1 - update to version 2.24.0 (fixes fedora#2468438) * Fri Jun 12 2026 Yaakov Selkowitz - 2.22.0-6 - Rebuilt for openssl 4.0 * Thu Jun 4 2026 Python Maint - 2.22.0-5 - Rebuilt for Python 3.15 * Wed May 6 2026 Miro Hrončok - 2.22.0-4 - Properly filter out test dependency on uvloop and python-pkcs11

[ 1 ] Bug #2468438 - python-asyncssh-2.24.0 is available [ 2 ] Bug #2498421 - CVE-2026-54590 python-asyncssh: AsyncSSH: Unauthorized file modification via authorized-keys directory escape [fedora-all] [ 3 ] Bug #2498423 - CVE-2026-54590 python-asyncssh: AsyncSSH: Unauthorized file modification via authorized-keys directory escape [fedora-all] [ 4 ] Bug #2498488 - CVE-2026-54591 python-asyncssh: AsyncSSH: Arbitrary file write via path traversal in SCP client [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1f248487e4' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities

Companies (1)

CWE Weaknesses (1)

Tools (2)