CVE-2026-35385

ADVISORY - nist

Summary

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Preservation of Permissions


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in