REDHAT-BUG-2224173: High severity openssh vulnerability
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2224173?
The severity of REDHAT-BUG-2224173 is high due to the potential for remote code execution.
How do I fix REDHAT-BUG-2224173?
To fix REDHAT-BUG-2224173, upgrade to OpenSSH version 9.3p2 or later.
What systems are affected by REDHAT-BUG-2224173?
REDHAT-BUG-2224173 affects versions of OpenSSH prior to 9.3p2 on various systems.
What causes the vulnerability in REDHAT-BUG-2224173?
The vulnerability in REDHAT-BUG-2224173 is caused by an insufficiently trustworthy search path in the PKCS#11 feature of ssh-agent.
Can REDHAT-BUG-2224173 be exploited by an attacker?
Yes, REDHAT-BUG-2224173 can be exploited by an attacker if an agent is forwarded to a system they control.