ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (A configuration file that provides a complete literal username is not categorized as an untrusted source.)
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:23479 https://access.redhat.com/errata/RHSA-2025:23479
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:23480 https://access.redhat.com/errata/RHSA-2025:23480
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:23481 https://access.redhat.com/errata/RHSA-2025:23481
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:0693 https://access.redhat.com/errata/RHSA-2026:0693
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:0976 https://access.redhat.com/errata/RHSA-2026:0976