CVE-2026-39828

Public on 2026-05-22
Modified on 2026-05-22
Description
When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.4
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core amazon-cloudwatch-agent Pending Fix
Amazon Linux 2023 amazon-cloudwatch-agent Pending Fix
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra containerd Pending Fix
Amazon Linux 2 - Docker Extra containerd Pending Fix
Amazon Linux 2 - Ecs Extra containerd Pending Fix
Amazon Linux 2023 containerd Pending Fix
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra docker Pending Fix
Amazon Linux 2 - Docker Extra docker Pending Fix
Amazon Linux 2 - Ecs Extra docker Pending Fix
Amazon Linux 2023 docker Pending Fix
Amazon Linux 2023 git-lfs Pending Fix
Amazon Linux 2 - Core nerdctl 2026-06-08 ALAS2-2026-3334 Fixed
Amazon Linux 2023 nerdctl 2026-06-08 ALAS2023-2026-1788 Fixed
Amazon Linux 2 - Core rclone Pending Fix
Amazon Linux 2023 rclone 2026-06-08 ALAS2023-2026-1810 Fixed
Amazon Linux 2 - Docker Extra runfinch-finch 2026-06-08 ALAS2DOCKER-2026-128 Fixed
Amazon Linux 2023 runfinch-finch 2026-06-08 ALAS2023-2026-1809 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N