In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode). | |
| First Time appeared |
Openbsd
Openbsd openssh |
|
| Weaknesses | CWE-281 | |
| CPEs | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openbsd
Openbsd openssh |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-02T18:15:37.128Z
Reserved: 2026-04-02T16:30:59.107Z
Link: CVE-2026-35385
Updated: 2026-04-02T17:06:11.715Z
Status : Received
Published: 2026-04-02T17:16:27.450
Modified: 2026-04-02T17:16:27.450
Link: CVE-2026-35385
No data.
OpenCVE Enrichment
No data.
Weaknesses