CVE-2023-28531: Critical severity OpenBSD OpenSSH vulnerability
Last updated 24 July 2024
Other sources
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:8.4p1-5+deb11u3Fixed in 1:8.4p1-5+deb11u4Fixed in 1:9.2p1-2+deb12u5Fixed in 1:10.0p1-2 - Upgrade
Upgrade
OpenSSH ssh-addto a version that resolves this vulnerability.Fixed in 9.3
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28531?
The severity of CVE-2023-28531 is critical (9.8).
What is the affected software for CVE-2023-28531?
The affected software for CVE-2023-28531 includes OpenSSH versions before 9.3, Brocade Fabric Operating System, HCI Bootstrap OS, and SolidFire Element OS.
How does CVE-2023-28531 impact ssh-add in OpenSSH?
CVE-2023-28531 allows smartcard keys to be added to ssh-agent without the intended per-hop destination constraints.
What is the earliest affected version of OpenSSH for CVE-2023-28531?
The earliest affected version of OpenSSH for CVE-2023-28531 is 8.9.
Where can I find more information about CVE-2023-28531?
You can find more information about CVE-2023-28531 at the following references: [1] https://security.gentoo.org/glsa/202307-01 [2] https://security.netapp.com/advisory/ntap-20230413-0008/ [3] https://www.openwall.com/lists/oss-security/2023/03/15/8