Skip to content
Ubuntu Openssh Security Advisory USN-8721

Ubuntu Openssh Security Advisory USN-8721

Linuxsecurity LinuxSecurity Advisories September 3, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

Several security issues were fixed in OpenSSH. Software Description: - openssh: secure shell (SSH) for secure access to remote machines Details: It was discovered that OpenSSH's ssh-agent incorrectly handled interactions between agent locking and the [email protected] extension. A remote attacker with access to a forwarded agent connection could possibly use this issue to perform operations that should only be available locally, such as adding tokens or using keys. (CVE-2026-73281) It was discovered that OpenSSH's ssh client incorrectly handled concurrent remote-forwarding operations. A remote attacker could possibly use this issue to cause a use-after-free condition, resulting in a denial of service or the execution of arbitrary code. (CVE-2026-73282) It was discovered that OpenSSH's sshd server incorrectly applied the restrict keyword from authorized_keys to tunnel forwarding requests. A local attacker with an authorized key could possibly use this issue to bypass int... Read the Full Advisory

Several security issues were fixed in OpenSSH.

Software Description:

- openssh: secure shell (SSH) for secure access to remote machines

It was discovered that OpenSSH's ssh-agent incorrectly handled interactions

between agent locking and the [email protected] extension. A remote

attacker with access to a forwarded agent connection could possibly use

this issue to perform operations that should only be available locally,

such as adding tokens or using keys. (CVE-2026-73281)

It was discovered that OpenSSH's ssh client incorrectly handled concurrent

remote-forwarding operations. A remote attacker could possibly use this

issue to cause a use-after-free condition, resulting in a denial of service

or the execution of arbitrary code. (CVE-2026-73282)

It was discovered that OpenSSH's sshd server incorrectly applied the

restrict keyword from authorized_keys to tunnel forwarding requests. A

local attacker with an authorized key could possibly use this issue to

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS openssh-client 1:10.2p1-2ubuntu3.6 openssh-server 1:10.2p1-2ubuntu3.6 Ubuntu 24.04 LTS openssh-client 1:9.6p1-3ubuntu13.19 openssh-server 1:9.6p1-3ubuntu13.19 Ubuntu 22.04 LTS openssh-client 1:8.9p1-3ubuntu0.17 openssh-server 1:8.9p1-3ubuntu0.17 After a standard system update you need to restart OpenSSH to make all the necessary changes.

CVE-2026-73281, CVE-2026-73282, CVE-2026-73283

Ubuntu Security Notice USN-8721-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Companies (1)

CWE Weaknesses (1)

Domains (1)

Email Addresses (1)

Platforms (2)