Skip to content
Critical Vulnerabilities in Fedora SSH Component Expose Users to Command Execution Risks

Critical Vulnerabilities in Fedora SSH Component Expose Users to Command Execution Risks

First seen 2 Jul 2026, 02:18 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 3, 2026 at 00:51 UTC
  • •Two critical vulnerabilities in Fedora's opkssh component were disclosed.
  • •CVE-2026-39828 allows unauthorized command execution via SSH.
  • •CVE-2026-39830 causes denial of service through resource leaks.

Fedora has released updates addressing two critical vulnerabilities in the opkssh component, identified as CVE-2026-39828 and CVE-2026-39830. Both vulnerabilities were published on May 22, 2026, and affect users of Fedora 43 and 44. CVE-2026-39828 allows unauthorized command execution due to improper handling of SSH permissions, while CVE-2026-39830 leads to denial of service through resource leaks from unsolicited SSH responses. The vulnerabilities can be exploited by attackers to gain unauthorized access or disrupt service. Users are advised to apply the updates using the 'dnf' package manager. The updates were made available on June 22, 2026, and are critical for maintaining system security.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 99d ago How this analysis works

Timeline

2026-05-22
CVE-2026-39828 and CVE-2026-39830 published
Fedora disclosed two critical vulnerabilities affecting opkssh, impacting SSH permissions and causing denial of service.
Linuxsecurity
2026-06-22
Updates released for Fedora 43 and 44
Fedora released updates to patch CVE-2026-39828 and CVE-2026-39830, urging users to upgrade via 'dnf'.
Linuxsecurity

More articles in this cluster (4)

Following this threat?

Track Fedora and CVE-2026-39828 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed