On 2026-07-22 12:01 UTC, Stuart Henderson <[email protected]> wrote: > On 2026-07-22, Raimo Niskanen <[email protected]> wrote: >> Does misc@ have any advice on how I should handle my security department, >> or possibly on how to "remedy these CVE:s"...? > > https://www.openssh.org/openbsd.html
For the specific problem at hand it's probably enough to s/OpenSSH_10.3/OpenSSH_10.4/ in the sshd link kit in /usr/share/relink Alternatively, block the IP address(es) where the scanner connects from. Another idea, since the scanner probably doesn't try to authenticate: PerSourcePenalties noauth:3650d Florian p.s. topinsights is an anagram of shitposting -- In my defence, I have been left unsupervised.

