Описание
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
A flaw was found in OpenSSH's ssh-agent component. A misinteraction between agent locking and the session-bind@openssh.com extension allows operations intended for local execution to be performed remotely. This could enable a remote attacker to add PKCS#11 tokens or utilize keys with destination restrictions, bypassing intended security controls.
Отчет
Red Hat has determined that this vulnerability has limited impact. Exploitation requires an authenticated SSH session with agent forwarding enabled and the agent in a locked state. Only OpenSSH versions 8.9 and later contain the vulnerable session-bind@openssh.com extension code. Red Hat Enterprise Linux 6, 7, 8, and RHEL 9 through 9.6 ship OpenSSH versions prior to 8.9 and are not affected. Red Hat may apply this fix in a future update for affected products.
Меры по смягчению последствий
Avoid using ssh-agent forwarding to untrusted remote hosts, or disable agent forwarding entirely by removing ForwardAgent yes from SSH configuration. If agent forwarding is required, avoid locking the agent while forwarded sessions are active.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | openssh | Affected | ||
| Red Hat Enterprise Linux 6 | openssh | Not affected | ||
| Red Hat Enterprise Linux 7 | openssh | Not affected | ||
| Red Hat Enterprise Linux 8 | openssh | Not affected | ||
| Red Hat Enterprise Linux 9 | openssh | Affected | ||
| Red Hat Hardened Images | openssh | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
3.5 Low
CVSS3
Связанные уязвимости
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
In ssh-agent in OpenSSH before 10.5, some operations can occur remotel ...
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
EPSS
3.5 Low
CVSS3