REDHAT-BUG-2454490: Medium severity OpenSSH OpenSSH vulnerability
Published Apr 2, 2026
·Updated
OpenSSH before 10.3 mishandles the authorizedkeys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
Affected Software
1 affected component
OpenSSH OpenSSH<10.3
Event History
Apr 2, 2026
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2454490?
REDHAT-BUG-2454490 is classified as a high severity vulnerability due to the potential for unauthorized access.
2
How do I fix REDHAT-BUG-2454490?
To fix REDHAT-BUG-2454490, upgrade OpenSSH to version 10.3 or later.
3
Which versions of OpenSSH are affected by REDHAT-BUG-2454490?
OpenSSH versions prior to 10.3 are affected by REDHAT-BUG-2454490.
4
What specific issue does REDHAT-BUG-2454490 cause?
REDHAT-BUG-2454490 mishandles the authorized_keys principals option in specific scenarios, leading to possible authentication issues.
5
Is REDHAT-BUG-2454490 linked to a Certificate Authority?
Yes, REDHAT-BUG-2454490 is related to scenarios involving a principals list in conjunction with a Certificate Authority.