USN-8804-1: OpenSSH vulnerabilities
Cosa significa
Ubuntu ha rilasciato un avviso di sicurezza (USN-8804-1) relativo a diverse vulnerabilità in OpenSSH. Le vulnerabilità permettono a un attaccante di eseguire comandi arbitrari, bypassare restrizioni di sicurezza, modificare file non autorizzati e causare denial of service. Le vulnerabilità colpiscono specifiche versioni di Ubuntu (14.04 LTS, 18.04 LTS, 20.04 LTS). Le patch sono disponibili tramite Ubuntu Pro.
Perché conta
Le vulnerabilità in OpenSSH possono portare a compromissioni di sistemi, accessi non autorizzati e danni operativi per PMI italiane che utilizzano Ubuntu. La mancanza di patch potrebbe esporre le infrastrutture a attacchi mirati.
Azioni consigliate
- Applicare le patch disponibili tramite Ubuntu Pro per le versioni interessate
- Verificare le configurazioni SSH per eventuali parametri non default
- Limitare l'accesso SSH a utenti specifici e verificare i permessi
- Abilitare il log dettagliato per le connessioni SSH
- Monitorare le attività di download e upload tramite SFTP
- Ridurre l'esposizione di servizi SSH a reti interne
- Eseguire un backup regolare e testare la ripristinabilità
Benefici operativi potenziali
- Riduzione della superficie esposta a attacchi SSH
- Miglioramento della gestione delle credenziali e delle configurazioni
- Riduzione del rischio di accessi non autorizzati e danni operativi
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
Florian Kohnhäuser discovered that OpenSSH incorrectly handled shell metacharacters in certain usernames. An attacker could possibly use this issue to execute arbitrary commands when certain non-default configurations were used, resulting in arbitrary code execution. This issue only affected Ubuntu 14.04 LTS. (CVE-2026-35386) Christos Papakonstantinou discovered that OpenSSH incorrectly handled ECDSA algorithm restrictions. An attacker could possibly use this issue to cause unintended ECDSA algorithms to be accepted, resulting in security restrictions being bypassed. (CVE-2026-35387) Vladimir Tokarev discovered that OpenSSH incorrectly handled certain principal restrictions in authorized_keys files. An attacker could possibly use this issue to bypass principal restrictions, resulting in unauthorized access. This issue only affected Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-35414) It was discovered that OpenSSH incorrectly handled downloaded file paths when using sftp with an untrusted server. An attacker could possibly use this issue to write downloaded files outside the intended location, resulting in unauthorized file modification. (CVE-2026-59995) It was discovered that OpenSSH incorrectly handled command-line arguments in internal-sftp. An attacker could possibly use this issue to cause certain security-related arguments to be ignored, resulting in security restrictions being bypassed. (CVE-2026-59997) It was discovered that OpenSSH incorrectly handled GSSAPIStrictAcceptorCheck when used with Windows Active Directory. An attacker could possibly use this issue to bypass GSSAPI security restrictions, resulting in unauthorized access. (CVE-2026-59998) It was discovered that OpenSSH incorrectly handled forwarding restrictions when DisableForwar
- Fonte
- Ubuntu Security Notices
- Entità pubblicatrice
- Ubuntu Security
- Tipo entità
- vendor security
- Area
- Global
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 22/09/2026 16:24
- MITRE ATT&CK
- T1562
- CVE
- CVE-2026-35386, CVE-2026-35387, CVE-2026-35414, CVE-2026-59995, CVE-2026-59997, CVE-2026-59998
Prodotti e versioni interessati
Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.