OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:12389 https://access.redhat.com/errata/RHSA-2026:12389
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:13380 https://access.redhat.com/errata/RHSA-2026:13380
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:13381 https://access.redhat.com/errata/RHSA-2026:13381
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:13383 https://access.redhat.com/errata/RHSA-2026:13383
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:16059 https://access.redhat.com/errata/RHSA-2026:16059