Fedora Releases Important Security Fixes for Putty Vulnerabilities

Fedora Releases Important Security Fixes for Putty Vulnerabilities

First seen 10 Jun 2026, 04:13 UTC Linuxsecuritywww.chiark.greenend.org.uk 97% similarity 60.6

Article Content

Browse articles
ThreatCluster

On May 25, 2026, Fedora released updates for Putty addressing multiple security vulnerabilities, including CVE-2026-48850, a double free vulnerability in RSA KEX code, CVE-2026-48851, which affects TELNET session data, and CVE-2026-48852, an assertion failure in ECDSA signature verification. These vulnerabilities could potentially allow attackers to exploit the affected systems. The updates are available for Fedora 43 and 44, and users are advised to upgrade using the 'dnf' update program. The vulnerabilities were reported in Bugzilla under various identifiers, confirming their existence and the need for immediate action. The updates are critical for maintaining the security of systems using the Putty application. Users are encouraged to apply the patches promptly to mitigate risks.

Key Points: • Fedora released security updates for Putty on May 25, 2026, addressing critical vulnerabilities. • CVE-2026-48850 involves a double free vulnerability in RSA KEX code. • Users of Fedora 43 and 44 are urged to upgrade to protect against these vulnerabilities.

ThreatCluster AI

Timeline

2026-05-25
Fedora updates Putty for security vulnerabilities
Fedora released updates for Putty, fixing CVE-2026-48850, CVE-2026-48851, and CVE-2026-48852, which affect the security of the application.
Linuxsecurity
2026-05-25
CVE-2026-48850 published
CVE-2026-48850 details a double free vulnerability in the RSA KEX code of Putty, potentially exploitable by attackers.
Linuxsecurity
2026-05-25
CVE-2026-48851 published
CVE-2026-48851 affects TELNET session data, marking it with trust sigils after proxy authentication, raising security concerns.
Linuxsecurity
2026-05-25
CVE-2026-48852 published
CVE-2026-48852 describes an assertion failure in ECDSA signature verification, which could lead to security issues.
Linuxsecurity

Community

Browse all →