CVE-2026-106588
Published: October 9, 2026Last modified: October 9, 2026
Description
In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 3.1 |
| Attack Vector | NETWORK |
| Attack complexity | HIGH |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | NONE |
| Integrity impact | LOW |
| Availability impact | NONE |
| Vector | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | openssh | Not affected (9.1_p1-r3) |
| 25 LTS | openssh | Not affected (10.0_p1-r7) | |
| Stream | openssh | Not affected (9.3_p1-r7) |