Database/Kernel, userspace & hypervisor

OpenSSH sftp: malicious server can write files outside the target directory during recursive copy
Impact
In sftp before 10.6 a server controls path elements that the client trusts during a recursive copy, so files can land outside the directory the operator chose. The exposure in a datacenter is automation that pulls artifacts over sftp - model weights, dataset shards, firmware bundles, backup restores - often running as a privileged service account on a management or build host. A traversal write under that account can overwrite scripts or configuration that later run on the fleet. The record rates it integrity and availability only, high attack complexity, and it requires the operator to initiate a recursive copy from a server the attacker controls.
Who can reach it
A malicious or compromised sftp server, acting against a client that starts a recursive copy from it. No authentication to the client is needed; user interaction (running the copy) is.
What to do
Upgrade the OpenSSH client package to 10.6 or a distribution backport. No daemon or node restart is required - the fix lands in the sftp binary and applies to the next copy. Until then, run recursive sftp pulls from untrusted endpoints only under an unprivileged account in a throwaway directory.
References
Related entries
- Linux kernel (drivers/iommu/amd): The AMD-Vi PPR (peripheral page request) notifier looked up the faulting PCI deviceCVE-2022-50505 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (net/tls): Tls_sw_recvmsg takes a psock reference before acquiring the reader lock and returns withoutCVE-2024-35908 · Linux kernel (net/tls)Medium
- Linux kernel (drivers/pci): Every write to a device's reset_method sysfs attribute that contains no space leaks theCVE-2024-56745 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/vfio/pci/pds): The pds VFIO variant driver shipped without a detach_ioas operation, so it had noCVE-2025-38625 · Linux kernel (drivers/vfio/pci/pds)Medium
- VMware Tools: A fully compromised ESXi host can force VMware Tools to skip host-to-guest authenticationCVE-2023-20867 · VMware ToolsLow
- OpenSSH before 10.6: LZ77 dictionary coder usable despite compression side-channel findingsCVE-2026-106582 · OpenSSH sshd and ssh (LZ77 dictionary coder in the compression path)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.