CVE-2026-35385

Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (ROCm)

Beschreibung

In OpenSSH vor Version 10.3 kann eine mit `scp` heruntergeladene Datei als setuid oder setgid installiert werden, was dem Erwartungsbild einiger Benutzer widerspricht, wenn der Download als root mit `-O` (Legacy-SCP-Protokoll) und ohne `-p` (Erhaltungsmodus) durchgeführt wird.

Metriken

Severity
high
kein öffentlicher PoC bekannt
8.1
Quelle: nvd-v3
45.0 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.6 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-06-25 19:30 UTC
CWE-281

Weakness-Klassen (CWE)

  • CWE-281Base

    Improper Preservation of Permissions

    The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-01 13:19 UTC· cve@mitre.org
    • Reference: https://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2
    • Reference: https://www.openssh.org/releasenotes.html#10.3p1
    • Reference: https://www.openwall.com/lists/oss-security/2026/04/02/3
    • Reference: https://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2
  2. CVE Modified2026-09-01 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/35xxx/CVE-2026-35385.json">CVE-2026-35385</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:12389
    • Reference: https://access.redhat.com/errata/RHSA-2026:13380
    • Reference: https://access.redhat.com/errata/RHSA-2026:13381
  3. CVE Modified2026-08-25 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:58981
  4. CVE Translated2026-07-24 21:10 UTC· nvd@nist.gov
    • Translation: Title: OpenSSH de OpenBSD, Description: En OpenSSH antes de 10.3, un archivo descargado por scp puede ser instalado setuid o setgid, un resultado contrario a las expectativas de algunos usuarios, si la descarga se realiza como root con -O (protocolo scp heredado) y sin -p (modo de preservación).

Betroffene Betriebssysteme

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_ai3.0

  • linux

    ubuntu / jqbionic

  • linux

    ubuntu / jqfocal

  • linux

    ubuntu / popplerjammy

  • linux

    ubuntu / popplernoble

  • linux

    ubuntu / popplerquesting

  • linux

    ubuntu / popplerresolute

  • other

    siemens / sinec_os

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • cryptography.io

    cryptography45.0.0 – 46.0.7

  • encode

    starlette0.8.3 – 1.0.1

  • encode

    starlette1.1.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • jqlang

    jq2026-04-12

  • libcap_project

    libcap

  • libsndfile_project

    libsndfile

  • libtiff

    libtiff

  • openbsd

    openssh10.3

  • openexr

    openexr3.1.0 – 3.2.7

  • openexr

    openexr3.3.0 – 3.3.9

  • openexr

    openexr3.4.0 – 3.4.9

  • pyasn1

    pyasn10.6.2

  • pyjwt_project

    pyjwt2.13.0

  • pypi

    vllm0.0.1

  • pypi

    vllm0.1.0

  • pypi

    vllm0.10.0

  • pypi

    vllm0.10.1

  • pypi

    vllm0.10.1.1

  • pypi

    vllm0.10.2

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-35385
Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (ROCm) — CVE-2026-35385 | NEOSEC Intel