Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73283

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

A flaw was found in OpenSSH's sshd component. The restrict keyword, designed to limit tunnel forwarding within the authorized_keys file, was not correctly enforced for tunnel forwarding. This issue could allow a local attacker to bypass intended security restrictions, potentially leading to unauthorized network access or resource usage through tunnels.

Отчет

An authorization bypass flaw was found in OpenSSH's sshd daemon. When processing SSH public key authentication, sshd fails to enforce the restrict keyword in authorized_keys against TUN/TAP tunnel forwarding requests. An authenticated user holding a restricted key can still establish virtual network interface tunnels if tunnel forwarding is globally enabled on the server. This allows authorized users to bypass intended per-key restriction policies, posing a Moderate impact to confidentiality and integrity.

Меры по смягчению последствий

Set PermitTunnel no in /etc/ssh/sshd_config to disable TUN/TAP tunnel forwarding server-wide. Alternatively, restrict tunnel permissions for specific users or groups using Match blocks in sshd_config or explicit no-tun directives in authorized_keys.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10opensshFix deferred
Red Hat Enterprise Linux 6opensshFix deferred
Red Hat Enterprise Linux 7opensshFix deferred
Red Hat Enterprise Linux 8opensshFix deferred
Red Hat Enterprise Linux 9opensshFix deferred
Red Hat Hardened ImagesopensshAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-305
https://bugzilla.redhat.com/show_bug.cgi?id=2514321openssh: OpenSSH: Tunnel forwarding restriction bypass

EPSS

Процентиль: 0%
0.00083
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 2.5
ubuntu
17 дней назад

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

CVSS3: 2.5
nvd
17 дней назад

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

msrc
5 дней назад

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

CVSS3: 2.5
debian
17 дней назад

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_ke ...

CVSS3: 2.5
github
17 дней назад

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

EPSS

Процентиль: 0%
0.00083
Низкий

5.4 Medium

CVSS3

Уязвимость CVE-2026-73283