Upgrade Upgrade openSSH to 9.7

Discussion in 'Install & Upgrades or Pre-Install Questions' started by Andy, Apr 23, 2024.

    I need to do a server scan to satisfy requirements by Clover because I process credit card on my site.
    One of the many items they want me to address is to upgrade the server open SSH version to the latest version which is 9.7
    Currently, I only have OpenSSH_8.7p1 installed.
    What is the correct way to upgrade this on Almalinux?

    AlmaLinux/Rocky Linux and RedHat all backport patches into their YUM RPMs they provide while keeping the versions the same most of the time. OpenSSH is one these YUM packages. So there is no OpenSSH 9.x upgrade route that would work without breaking your server.

    excerpt of the change log for AlmaLinux OpenSSL 8.7p1
    Code (Text):
    rpm -qa --changelog openssh | head -n21
    * Mon Jan 08 2024 Dmitry Belyavskiy <> - 8.7p1-34.3
    - rebuilt
    * Mon Jan 08 2024 Dmitry Belyavskiy <> - 8.7p1-34.2
    - Fix Terrapin attack
      Resolves: RHEL-19764
    * Thu Dec 21 2023 Dmitry Belyavskiy <> - 8.7p1-34.1
    - Fix Terrapin attack (CVE-2023-48795)
      Resolves: RHEL-19764
    - Forbid shell metasymbols in username/hostname (CVE-2023-51385)
      Resolves: RHEL-19822
    * Thu Jul 20 2023 Dmitry Belyavskiy <> - 8.7p1-34
    - Avoid remote code execution in ssh-agent PKCS#11 support
      Resolves: CVE-2023-38408
    * Tue Jun 13 2023 Dmitry Belyavskiy <> - 8.7p1-33
    - Allow specifying validity interval in UTC
      Resolves: rhbz#2115043

    Example Jan 8 changelog is for CVE-2023-51385 : In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and for OpenSSH <9.6 security fixes backported to OpenSSH 8.7p1. So AFAIK OpenSSH 8.7p1 has security posture equivalent to OpenSSH 9.6 at least oss-security - Announce: OpenSSH 9.6 released

    OpenSSH 9.7 was a bug fix and new feature release with no security updates AFAIK OpenSSH: Release Notes