RHSA-2023:3839: Moderate: libssh security update
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.Security Fix(es): libssh: NULL pointer dereference during rekeying with algorithm guessing (CVE-2023-1667) libssh: authorization bypass in pkiverifydatasignature (CVE-2023-2283) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libsshto a version that resolves this vulnerability.Fixed in 0.9.6-10.el8_8 - Upgrade
Upgrade
redhat/libssh-configto a version that resolves this vulnerability.Fixed in 0.9.6-10.el8_8 - Upgrade
Upgrade
redhat/libssh-debuginfoto a version that resolves this vulnerability.Fixed in 0.9.6-10.el8_8 - Upgrade
Upgrade
redhat/libssh-debugsourceto a version that resolves this vulnerability.Fixed in 0.9.6-10.el8_8 - Upgrade
Upgrade
redhat/libssh-develto a version that resolves this vulnerability.Fixed in 0.9.6-10.el8_8 - Upgrade
Upgrade
redhat/libsshto a version that resolves this vulnerability.Fixed in 0.9.6-10.el8_8.aa - Upgrade
Upgrade
redhat/libssh-debuginfoto a version that resolves this vulnerability.Fixed in 0.9.6-10.el8_8.aa - Upgrade
Upgrade
redhat/libssh-debugsourceto a version that resolves this vulnerability.Fixed in 0.9.6-10.el8_8.aa - Upgrade
Upgrade
redhat/libssh-develto a version that resolves this vulnerability.Fixed in 0.9.6-10.el8_8.aa - Upgrade
Upgrade
libsshto a version that resolves this vulnerability.Patch CVE-2023-2283 - Upgrade
Upgrade
libsshto a version that resolves this vulnerability.Patch CVE-2023-1667 - Operational
After installing the updated libssh packages, restart all running applications using libssh so the update takes effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:3839?
The severity of RHSA-2023:3839 is categorized as important due to the vulnerabilities in the libssh library.
How do I fix RHSA-2023:3839?
To fix RHSA-2023:3839, you need to update the libssh package to version 0.9.6-10.el8_8 or later.
What vulnerabilities are addressed in RHSA-2023:3839?
RHSA-2023:3839 addresses vulnerabilities including a NULL pointer dereference and an authorization bypass during rekeying.
Which systems are affected by RHSA-2023:3839?
RHSA-2023:3839 affects systems running the libssh package versions prior to 0.9.6-10.el8_8.
Is there a workaround for RHSA-2023:3839?
There are no official workarounds for RHSA-2023:3839; updating the affected packages is the recommended action.