USN-8514-2: OpenSSH vulnerability

Publication date

16 September 2026

Overview

OpenSSH could be made to overwrite files as the administrator.


Packages

  • openssh - secure shell (SSH) for secure access to remote machines

Details

USN-8514-1 fixed a vulnerability in OpenSSH. This update provides
the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS.

Original advisory details:

It was discovered that OpenSSH incorrectly handled file permissions when
downloading files as root using the legacy scp protocol without the
preserve-mode option. An attacker could use this to install setuid or setgid
files on a system, possibly leading to privilege escalation.

USN-8514-1 fixed a vulnerability in OpenSSH. This update provides
the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS.

Original advisory details:

It was discovered that OpenSSH incorrectly handled file permissions when
downloading files as root using the legacy scp protocol without the
preserve-mode option. An attacker could use this to install setuid or setgid
files on a system, possibly leading to privilege escalation.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
20.04 LTS focal openssh-client –  1:8.2p1-4ubuntu0.13+esm2  
openssh-server –  1:8.2p1-4ubuntu0.13+esm2  
18.04 LTS bionic openssh-client –  1:7.6p1-4ubuntu0.7+esm5  
openssh-server –  1:7.6p1-4ubuntu0.7+esm5  
14.04 LTS trusty openssh-client –  1:6.6p1-2ubuntu2.13+esm3  
openssh-server –  1:6.6p1-2ubuntu2.13+esm3  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›