Updated putty packages fix security vulnerabilities
Publication date: 15 Jun 2026Modification date: 15 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-4115
Description
ECDSA signature verification can be made to fail an assertion.
Server can provoke a double free in RSA KEX code.
Telnet session data is marked with trust sigils after authenticating to
a proxy.
PuTTY Ed25519 Signature ecc-ssh.c eddsa_verify signature verification.
(CVE-2026-4115)
References
- https://bugs.mageia.org/show_bug.cgi?id=35585
- https://www.openwall.com/lists/oss-security/2026/05/24/11
- https://lists.tartarus.org/pipermail/putty-announce/2026/000042.html
- https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/rsakex-double-free.html
- https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/telnet-trust-sigil.html
- https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/eddsa-overlarge-s.html
- https://www.cve.org/CVERecord?id=CVE-2026-4115
SRPMS
9/core
- putty-0.84-1.mga9