From 8268f997d3a818f2fdbd80cddff2024f63ebf01c Mon Sep 17 00:00:00 2001 From: Solar Designer Date: Sat, 16 Mar 2024 22:25:53 +0100 Subject: [PATCH] openssh-8.7p1-34.3.el9_3.security.0.3 --- docs/news.md | 2 +- docs/packages/openssh.md | 7 ++++++- 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/docs/news.md b/docs/news.md index c5350bc..7a2a6e0 100644 --- a/docs/news.md +++ b/docs/news.md @@ -2,7 +2,7 @@ These are what we consider significant SIG/Security news items, not an exhaustive list of package updates and wiki edits. -## March 11, 2024 +## March 11 to 16, 2024 [openssh](packages/openssh.md) rebased on upstream EL 8.7p1-34.3 with fixes for CVE-2023-48795 (Terrapin attack) and CVE-2023-51385, now building it without Kerberos support (further shortens `ldd sshd` from 20 to 13 lines, down from 28 lines in upstream EL). diff --git a/docs/packages/openssh.md b/docs/packages/openssh.md index 6a6a22b..68e7486 100644 --- a/docs/packages/openssh.md +++ b/docs/packages/openssh.md @@ -2,7 +2,7 @@ ## EL9 -- Version `8.7p1-34.3.el9_3.security.0.2` +- Version `8.7p1-34.3.el9_3.security.0.3` - Based on `8.7p1-34.el9_3.3` ### Changes summary @@ -13,6 +13,11 @@ ### Change log ``` +* Sat Mar 16 2024 Solar Designer 8.7p1-34.3.el9_3.security.0.3 +- Comment out GSSAPI* lines in /etc/ssh/ssh*_config.d/50-redhat.conf and patch + the code to silently ignore GSSAPIKexAlgorithms when unsupported (like it is + in our new without-Kerberos build) + * Mon Mar 11 2024 Solar Designer 8.7p1-34.3.el9_3.security.0.2 - Rebase 8.7p1-34.el9_3.security.0.1 on 8.7p1-34.3 - Build without Kerberos support (shortens "ldd sshd" from 20 to 13 lines)