CVE-2026-106588

Published: October 9, 2026Last modified: October 9, 2026

Description

In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected.

Severity score breakdown

ParameterValue
Base score3.1
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopensshNot affected (9.1_p1-r3)
25 LTSopensshNot affected (10.0_p1-r7)
StreamopensshNot affected (9.3_p1-r7)

References

ON THIS PAGE