Описание
The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 0.52.0-1 |
| esm-apps/bionic | not-affected | |
| esm-apps/focal | released | 1:0.0~git20200221.2aa609c-1ubuntu0.1~esm2 |
| esm-apps/jammy | released | 1:0.0~git20211202.5770296-1ubuntu0.1~esm2 |
| esm-apps/noble | released | 1:0.19.0-1ubuntu0.1~esm2 |
| esm-apps/resolute | released | 1:0.47.0-1ubuntu0.1~esm1 |
| esm-infra-legacy/xenial | not-affected | |
| jammy | needed | |
| noble | needed | |
| questing | ignored | end of life, was needed |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 20250506.01-0ubuntu3 |
| esm-apps-legacy/xenial | released | 20240716.00-0ubuntu1~16.04.0+esm3 |
| esm-apps/bionic | released | 20241011.01-0ubuntu1~18.04.0+esm3 |
| esm-infra/focal | released | 20250116.00-0ubuntu1~20.04.0+esm3 |
| jammy | released | 20250116.00-0ubuntu1~22.04.3 |
| noble | released | 20250116.00-0ubuntu1~24.04.4 |
| questing | released | 20250506.01-0ubuntu1.2 |
| resolute | released | 20250506.01-0ubuntu2.1 |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps/focal | not-affected | code-not-present |
| esm-infra-legacy/xenial | needed | |
| esm-infra/bionic | needed | |
| jammy | DNE | |
| noble | DNE | |
| questing | DNE | |
| resolute | DNE | |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-infra-legacy/xenial | needs-triage | |
| esm-infra/bionic | needs-triage | |
| esm-infra/focal | needs-triage | |
| jammy | needs-triage | |
| noble | needs-triage | |
| questing | ignored | end of life, was needs-triage |
| resolute | needs-triage | |
| snap | needs-triage | |
| upstream | needs-triage |
Показывать по
Ссылки на источники
EPSS
9.1 Critical
CVSS3
Связанные уязвимости
The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nis ...
EPSS
9.1 Critical
CVSS3