Описание
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
A flaw was found in OpenSSH's sshd component. The restrict keyword, designed to limit tunnel forwarding within the authorized_keys file, was not correctly enforced for tunnel forwarding. This issue could allow a local attacker to bypass intended security restrictions, potentially leading to unauthorized network access or resource usage through tunnels.
Отчет
An authorization bypass flaw was found in OpenSSH's sshd daemon. When processing SSH public key authentication, sshd fails to enforce the restrict keyword in authorized_keys against TUN/TAP tunnel forwarding requests. An authenticated user holding a restricted key can still establish virtual network interface tunnels if tunnel forwarding is globally enabled on the server. This allows authorized users to bypass intended per-key restriction policies, posing a Moderate impact to confidentiality and integrity.
Меры по смягчению последствий
Set PermitTunnel no in /etc/ssh/sshd_config to disable TUN/TAP tunnel forwarding server-wide. Alternatively, restrict tunnel permissions for specific users or groups using Match blocks in sshd_config or explicit no-tun directives in authorized_keys.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | openssh | Fix deferred | ||
| Red Hat Enterprise Linux 6 | openssh | Fix deferred | ||
| Red Hat Enterprise Linux 7 | openssh | Fix deferred | ||
| Red Hat Enterprise Linux 8 | openssh | Fix deferred | ||
| Red Hat Enterprise Linux 9 | openssh | Fix deferred | ||
| Red Hat Hardened Images | openssh | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_ke ...
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
EPSS
5.4 Medium
CVSS3