Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2026:2472-1 — apache-sshd (CVE-2020-36843 +1 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for apache-sshd, jpgpj

This update for apache-sshd, jpgpj fixes the following issues

  • CVE-2020-36843: no check performed on scalar to avoid signature malleability (bsc#1239551).
  • CVE-2026-48827: Apache MINA SSHD: Path traversal in org.apache.sshd: sshd-git (bsc#1267018).

Changes for jpgpj:

  • Initial packaging with v1.3

Changes for apache-sshd:

  • Update to upstream version 2.18.0
  • Bug Fixes

+ GH-743 Ensure the Java ServiceLoader use a singleton

SftpFileSystemProvider

+ GH-879 Close SSH channel gracefully on exception in port

forwarding

+ Security: Improve handling of repository paths in sshd-git.

Resolves CVE-2026-48827, bsc#1267018

  • New Features

+ GH-892 Align handling certificates without principals with

OpenSSH 10.3

  • Update to upstream version 2.17.1
  • Changes

+ GH-875 Use Apache Parent POM 36

  • Update to upstream version 2.17.0

+ GH-469, SSHD-897 Fix duplicate character echo with interactive

shells

+ GH-721 SSH client: schedule session timeout checks on demand

only

+ GH-807 Handle 'verified' flag for sk-* keys

+ GH-809 Fix server-side authentication for FIDO/U2F sk-* keys

with flags in authorized_keys

+ GH-827 Don't fail on invalid known_hosts lines; log and skip

them

+ GH-830 EC public keys: let Bouncy Castle generate X.509

encodings with the curve OID as algorithm parameter

+ GH-855 SFTP: use a single SftpClient per SftpFileSystem

+ GH-856 Fix using ed25519 with BC-FIPS

+ GH-861 SFTP client: prevent sending zero-length writes in

SftpOutputStreamAsync

+ SSHD-1348 Fix zero-length SFTP reads

+ SSHD-1349 Bump PMD to 7.20.0 to avoid StackOverflowError when

compiling on Java 26-ea

+ GH-814 Include a fix for CVE-2020-36843 (bsc#1239551) in

optional dependency net.i2p.crypto:eddsa:0.3.0: perform the

missing range check in Apache MINA SSHD before delegating to

the signature verification in net.i2p.crypto:eddsa:0.3.0.

This means that using net.i2p.crypto:eddsa:0.3.0 in Apache

MINA SSHD is safe despite that CVE in the dependency.

+ GH-865 replace %h in HostName SSH config

  • Update to upstream version 2.16.0
  • Changes of version 2.16.0

+ bugfix: fix cert auth failed bug

+ GH-664: Skip MAC negotiation if an AEAD cipher was negotiated

+ GH-663: Fix a race in IoSession creation

+ Also test sshd-mina using mina-core 2.2.4

+ ScpShell fixes; SFTP append mode for buggy servers

+ fix sources.jar Reproducible Builds issue

+ GH-700: Fix race in AbstractCloseable.doCloseImmediately()

+ GH-705: Make ChannelToPortHandler accessible to user code

+ GH-709: Handle keep-alive channel messages sent by an old

OpenSSH server

+ GH-727: supply default port for proxyJump if no

HostConfigEntry

+ GH-733: Fix SftpRemotePathChannel.transferTo

+ GH-725: Added commandTimeoutMillis in executeRemoteCommand

+ GH-774: Fix WritePendingException

+ #771 Avoid NoClassDefFoundError:

net/i2p/crypto/eddsa/EdDSAPublicKey

+ GH-516: Fix filesystem-id parsing in getFileSystem(URI)

+ GH-754: Don't close DefaultForwarder on bind error

+ Close repository after usage in GitPackCommand

+ Trigger ClientChannelEvent.Timeout and

ClientSessionEvent.TIMEOUT independently to host's program

cycle times

  • Changes of version 2.15.0

+ GH-618: Fix reading an OpenSshCertificate from a Buffer

+ Add interface to configure details of JGit's pack

implementation

+ ML-KEM key exchanges using Bouncy Castle 1.79

+ GH-628: Fix reading directories with trailing blanks in the

name

+ GH-626: Enable Streaming.Async for ChannelDirectTcpip

+ Sftp server 'ls' command timeout

+ GH-636: Handle unknown key types in known_hosts

+ GH-643: provide interfaces for caching file attributes on

paths

+ Bouncy Castle EdDSA / Ed25519 Support

+ Abstract revoked key handling in KnownHostsServerKeyVerifier

  • Fix an incompletely interpolated dependency with maven 4.0.0-rc-4
  • Fix wrong invocation of xmvn-subst
  • Updated to upstream version 2.14.0
  • Changes in version 2.14.0

+ GH-524 Performance improvements

+ GH-533 Fix multi-step authentication

+ GH-582 Fix filtering in NamedFactory

+ GH-587 Prevent NullPointerExceptionon closed channel in

NettyIoSession

+ GH-590 Better support for FIPS

+ GH-597 Pass on Charset in

ClientSession.executeRemoteCommand()

+ New utility methods SftpClient.put(Path localFile, String

remoteFileName) and SftpClient.put(InputStream in, String

remoteFileName) facilitate SFTP file uploading.

  • GH-590 Better support for FIPS

Besides fixing a bug with bc-fips (the RandomGenerator class

exists in normal Bouncy Castle, but not in the FIPS version,

but Apache MINA sshd referenced it even if only bc-fips was

present), support was improved for running in an environment

restricted by FIPS.

There is a new system property

org.apache.sshd.security.fipsEnabled. If set to true, a number

of crypto-algorithms not approved by FIPS 140 are disabled:

+ key exchange methods sntrup761x25519-sha512,

[email protected], curve25519-sha256,

[email protected],

Affected software

SUSE-SU-2026:2472-1 is recorded against 2 packages.

  • apache-sshd (fixed in 2.18.0-150200.5.11.1)
  • jpgpj (fixed in 1.3-150200.5.3.1)

Timeline and source

Published on 19 June 2026 and last revised on 20 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-06-19
Updated 2026-08-20
Modified 2026-06-20
Fix URL N/A

Affected Packages

Software From version Fixed in
apache-sshd 2.18.0-150200.5.11.1
jpgpj 1.3-150200.5.3.1

Free Vulnerability Check

Is your site affected by SUSE-SU-2026:2472-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:2472-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.