Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73281

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 3.5
EPSS Низкий

Описание

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

A flaw was found in OpenSSH's ssh-agent component. A misinteraction between agent locking and the session-bind@openssh.com extension allows operations intended for local execution to be performed remotely. This could enable a remote attacker to add PKCS#11 tokens or utilize keys with destination restrictions, bypassing intended security controls.

Отчет

Red Hat has determined that this vulnerability has limited impact. Exploitation requires an authenticated SSH session with agent forwarding enabled and the agent in a locked state. Only OpenSSH versions 8.9 and later contain the vulnerable session-bind@openssh.com extension code. Red Hat Enterprise Linux 6, 7, 8, and RHEL 9 through 9.6 ship OpenSSH versions prior to 8.9 and are not affected. Red Hat may apply this fix in a future update for affected products.

Меры по смягчению последствий

Avoid using ssh-agent forwarding to untrusted remote hosts, or disable agent forwarding entirely by removing ForwardAgent yes from SSH configuration. If agent forwarding is required, avoid locking the agent while forwarded sessions are active.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10opensshAffected
Red Hat Enterprise Linux 6opensshNot affected
Red Hat Enterprise Linux 7opensshNot affected
Red Hat Enterprise Linux 8opensshNot affected
Red Hat Enterprise Linux 9opensshAffected
Red Hat Hardened ImagesopensshAffected
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2514327openssh: OpenSSH: ssh-agent allows remote execution of local operations

EPSS

Процентиль: 5%
0.00158
Низкий

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 3.5
ubuntu
17 дней назад

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

CVSS3: 3.5
nvd
17 дней назад

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

msrc
14 дней назад

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

CVSS3: 3.5
debian
17 дней назад

In ssh-agent in OpenSSH before 10.5, some operations can occur remotel ...

CVSS3: 3.5
github
17 дней назад

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

EPSS

Процентиль: 5%
0.00158
Низкий

3.5 Low

CVSS3