USN-8804-1: OpenSSH vulnerabilities
Ubuntu patched two OpenSSH flaws, including command execution on 14.04 and an ECDSA bypass.
Ubuntu Security Notice USN-8804-1 covers two OpenSSH vulnerabilities. CVE-2026-35386 involves incorrect handling of shell metacharacters in certain usernames, which could allow arbitrary command execution, but only on Ubuntu 14.04 LTS and only with certain non-default configurations. CVE-2026-35387 involves incorrect ECDSA algorithm restrictions that could let unintended ECDSA algorithms be accepted and bypass security restrictions. The notice does not report active exploitation.
- CVE-2026-35386 allows command execution via metacharacters in usernames.
- That issue affects only Ubuntu 14.04 LTS with non-default configurations.
- CVE-2026-35387 can let unintended ECDSA algorithms be accepted.
- USN-8804-1 covers the OpenSSH fixes; active exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2026-353868.1<1%In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command linepublished · openbsd openssh+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-35386+1 related CVE | In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line |
Florian Kohnhäuser discovered that OpenSSH incorrectly handled shell metacharacters in certain usernames. An attacker could possibly use this issue to execute arbitrary commands when certain non-default configurations were used, resulting in arbitrary code execution. This issue only affected Ubuntu 14.04 LTS. (CVE-2026-35386) Christos Papakonstantinou discovered that OpenSSH incorrectly handled ECDSA algorithm restrictions. An attacker could possibly use this issue to cause unintended ECDSA algorithms to be accepted, resulting in security restrictions being bypassed. (CVE-2026-35387) Vladimir Tokarev discovered that OpenSSH incorrectly handled certain principal restrictions in…
This source does not provide full text. Read it at ubuntu.com.