VYPR

rpm package

opensuse/kit&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/kit&distro=openSUSE%20Tumbleweed

Vulnerabilities (4)

  • CVE-2026-39835MedMay 22, 2026
    affected < 0.107.0-1.1fixed 0.107.0-1.1

    SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

  • CVE-2026-39832CriMay 22, 2026
    affected < 0.107.0-1.1fixed 0.107.0-1.1

    When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now

  • CVE-2026-39831CriMay 22, 2026
    affected < 0.107.0-1.1fixed 0.107.0-1.1

    The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the

  • CVE-2026-39827MedMay 22, 2026
    affected < 0.107.0-1.1fixed 0.107.0-1.1

    An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state