Database/Kernel, userspace & hypervisor

OpenSSH sshd: the value "none" is sometimes treated as a filename instead of disabling the feature
Impact
Operators write none in sshd_config to switch a feature off; before 10.6 sshd sometimes read it as a path instead. The result is a daemon whose effective configuration differs from the one the operator reviewed and committed, which is exactly the failure mode that config-management and CIS-style hardening baselines are supposed to prevent across a fleet. The record rates it low integrity impact, local vector, high complexity, so the realistic consequence is a control silently not applied on hosts built from a hardening template rather than a direct break-in.
Who can reach it
Local, requiring low privileges per the record. The practical exposure is misconfiguration: any sshd whose config sets an option to none.
What to do
Upgrade to OpenSSH 10.6 and restart sshd. Before and after the upgrade, check the effective configuration with sshd -T on a representative node rather than trusting the file, and confirm that any option set to none is actually disabled. Package update plus daemon restart.
References
Related entries
- OpenSSH ssh-agent: locking bypass lets a forwarded remote session add tokens and use keysCVE-2026-73281 · OpenSSH ssh-agent (agent locking vs session-bind@openssh.com extension)Low
- Linux kernel mlx5_ib (create QP response): mlx5_ib_create_qp_resp is never initialized in create_qp_common, so creatingCVE-2018-20855 · Linux kernel mlx5_ib (create QP response)Low
- Xen on AMD Family 17h / Hygon Family 18h - guest SSBD selection: Setting Speculative Store Bypass Disable on AMD FamilyCVE-2022-42336 · Xen on AMD Family 17h / Hygon Family 18h - guest SSBD selectionLow
- SSSD autofs responder: improper buffer offset during request parsing causes out-of-bounds read and crashCVE-2026-104029 · SSSD autofs responder (request buffer offset calculation)Low
- OpenSSH sshd: restrict in authorized_keys does not disable tunnel forwarding as documentedCVE-2026-106586 · OpenSSH sshd (restrict keyword in authorized_keys, tunnel forwarding)Low
- OpenSSH sshd: restrict keyword in authorized_keys did not cover tunnel forwardingCVE-2026-73283 · OpenSSH sshd (authorized_keys restrict keyword vs tunnel forwarding)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.