Logo
vulnerabilityCVE-2026-35385
Name
CVE-2026-35385
Source
NVD ( link)Debian ( link)
Description
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dropbear
Patched

Vulnerability Ratings#


7.5
CVSSv31
8.1
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2026.93
Not Affected
buildroot
master
2026.94
Not Affected
openwrt
master
2026.94-r1
Not Affected
yocto
kirkstone
2020.81
Not Affected
yocto
master
2026.94
Not Affected
yocto
scarthgap
2022.83
Not Affected

Resolved with patches#


dropbear (openwrt:openwrt-25.12)

#
Title
Author
Resolve
1
scp: clear setuid/setgid bits on received files
Matt Johnston <matt@ucc.asn.au>
CVE-2026-35385