CVE-2023-51384

EUVD-2023-56105
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
openbsdopenssh
8.9 ≤
𝑥
< 9.6
debiandebian_linux
11.0
debiandebian_linux
12.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssh
bookworm
1:9.2p1-2+deb12u3
fixed
bookworm (security)
1:9.2p1-2+deb12u3
fixed
bullseye
1:8.4p1-5+deb11u3
not-affected
bullseye (security)
1:8.4p1-5+deb11u3
fixed
buster
not-affected
sid
1:9.9p1-3
fixed
trixie
1:9.9p1-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssh
bionic
not-affected
focal
not-affected
jammy
Fixed 1:8.9p1-3ubuntu0.6
released
lunar
Fixed 1:9.0p1-1ubuntu8.7
released
mantic
Fixed 1:9.3p1-1ubuntu3.2
released
noble
Fixed 1:9.6p1-3ubuntu1
released
oracular
Fixed 1:9.6p1-3ubuntu1
released
trusty
not-affected
xenial
not-affected
openssh-ssh1
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
lunar
ignored
mantic
ignored
noble
needs-triage
oracular
needs-triage
trusty
dne
xenial
dne