{"id":"ECHO-f8b1-1c2f-484d","upstream":["CVE-2026-106589"],"severity":[],"modified":"2026-10-07T15:00:06.170Z","affected":[{"package":{"ecosystem":"Echo","name":"openssh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:10.6p1-1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-106589"},{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-106589"}],"withdrawn":"2026-10-07T15:00:06.170Z","summary":"QNX 6 / SCO OpenServer 5 only. sshd-session can keep root privileges on\nplatforms that lack file-descriptor passing and need root for PTY\nallocation, via GatewayPorts and StreamLocalForwarding. Linux supports\nfile-descriptor passing, so this code path is not used in Echo's build.\nOpenSSH 10.6 also forcibly disables those options on the affected\nplatforms.\nhttps://www.openssh.com/releasenotes.html#10.6\nhttps://security-tracker.debian.org/tracker/CVE-2026-106589\n"}