Critical Vulnerabilities in Fedora's python-asyncssh Affect Multiple Versions

Critical Vulnerabilities in Fedora's python-asyncssh Affect Multiple Versions

First seen 20 Jul 2026, 07:01 UTC Linuxsecurity 85% similarity 70.5

Article Content

Browse articles
ThreatCluster

Fedora has released updates for python-asyncssh to address two critical vulnerabilities, CVE-2026-54590 and CVE-2026-54591, which allow unauthorized file modifications and arbitrary file writes through path traversal. These vulnerabilities affect versions 2.22.0 and earlier, with the latest patched version being 2.24.0. The vulnerabilities were published on July 8, 2026, and have been confirmed to impact systems using the authorized-keys directory escape method. Users are urged to update their systems to mitigate potential exploitation. The updates were made available through the 'dnf' package manager. The vulnerabilities could lead to significant security risks if left unaddressed, particularly in environments relying on SSH for secure communications.

Key Points: • CVE-2026-54590 allows unauthorized file modification via directory escape. • CVE-2026-54591 enables arbitrary file writes through path traversal in SCP client. • Users must upgrade to python-asyncssh version 2.24.0 to mitigate these vulnerabilities.

ThreatCluster AI

Timeline

2026-07-08
CVE-2026-54590 published
CVE-2026-54590 details unauthorized file modification via authorized-keys directory escape.
Linuxsecurity
2026-07-08
CVE-2026-54591 published
CVE-2026-54591 describes arbitrary file write via path traversal in SCP client.
Linuxsecurity
2026-07-11
Update to python-asyncssh 2.23.1 released
Fedora released version 2.23.1 to fix CVE-2026-54590 and CVE-2026-54591.
Linuxsecurity
2026-07-20
Update to python-asyncssh 2.24.0 released
Fedora released version 2.24.0 to address the vulnerabilities and improve security.
Linuxsecurity

Community

Browse all →