REDHAT-BUG-2454494
Published Apr 2, 2026
·Updated
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
Affected Software
1 affected component
OpenSSH OpenSSH<10.3
Event History
Apr 2, 2026
Data Sourced
via Red Hat·06:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2454494?
The severity of REDHAT-BUG-2454494 is considered high, as it can lead to the use of unintended ECDSA algorithms.
2
How do I fix REDHAT-BUG-2454494?
To fix REDHAT-BUG-2454494, upgrade OpenSSH to version 10.3 or later.
3
What software is affected by REDHAT-BUG-2454494?
The affected software includes OpenSSH versions prior to 10.3.
4
What vulnerability does REDHAT-BUG-2454494 describe?
REDHAT-BUG-2454494 describes a vulnerability where ECDSA algorithms are misinterpreted, potentially compromising security.
5
Is there a patch available for REDHAT-BUG-2454494?
Yes, patches to address REDHAT-BUG-2454494 are included in newer versions of OpenSSH beyond 10.3.