Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
FEDORA-2026-12d4cde449 (opkssh-0.14.0-3.fc43) has been submitted as an update to Fedora 43. https://bodhi.fedoraproject.org/updates/FEDORA-2026-12d4cde449
FEDORA-2026-7794729685 (opkssh-0.14.0-3.fc44) has been submitted as an update to Fedora 44. https://bodhi.fedoraproject.org/updates/FEDORA-2026-7794729685
I used the wrong bug id, FEDORA-2026-7794729685 does not actually fix this
CVE-2026-45287 is in go.opentelemetry.io/otel/schema (packages schema/v1.0 and schema/v1.1), which is a separately versioned Go module on the v0.0.x line, fixed in v0.0.17. It is not part of go.opentelemetry.io/otel despite the shared module path prefix. opkssh vendors go.opentelemetry.io/otel v1.35.0 (indirect, via zitadel/oidc), but does not depend on go.opentelemetry.io/otel/schema