REDHAT-BUG-2255850: Medium severity openssh vulnerability
OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mmanswerauthpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.
https://arxiv.org/abs/2309.02545 https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77 https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2255850?
The severity of REDHAT-BUG-2255850 is significant due to its potential to allow authentication bypass through row hammer attacks.
How do I fix REDHAT-BUG-2255850?
To fix REDHAT-BUG-2255850, update OpenSSH to version 9.7 or later, where the vulnerability is addressed.
What affected versions are known for REDHAT-BUG-2255850?
REDHAT-BUG-2255850 affects all OpenSSH versions up to and including 9.6.
What type of attack does REDHAT-BUG-2255850 allow?
REDHAT-BUG-2255850 allows row hammer attacks that can lead to authentication bypass.
Who is impacted by REDHAT-BUG-2255850?
Users deploying OpenSSH in environments with susceptible DRAM configurations are impacted by REDHAT-BUG-2255850.