Several vulnerabilities have been discovered in OpenSSH, an
implementation of the SSH protocol suite.
CVE-2021-41617
It was discovered that sshd failed to correctly initialise
supplemental groups when executing an AuthorizedKeysCommand or
AuthorizedPrincipalsCommand, where a AuthorizedKeysCommandUser or
AuthorizedPrincipalsCommandUser directive has been set to run the
command as a different user. Instead these commands would inherit
the groups that sshd was started with.
CVE-2023-28531
Luci Stanescu reported that a error prevented constraints being
communicated to the ssh-agent when adding smartcard keys to the
agent with per-hop destination constraints, resulting in keys being
added without constraints.
CVE-2023-48795
Fabian Baeumer, Marcus Brinkmann and Joerg Schwenk discovered that
the SSH protocol is prone to a prefix truncation attack, known as
the “Terrapin attack”. This attack allows a MITM attacker to effect
a limited break of the integrity of the early encrypted SSH
transport protocol by sending extra messages prior to the
commencement of encryption, and deleting an equal number of
consecutive messages immediately after encryption starts.
Details can be found at https://terrapin-attack.com/
CVE-2023-51384
It was discovered that when PKCS#11-hosted private keys were
added while specifying destination constraints, if the PKCS#11
token returned multiple keys then only the first key had the
constraints applied.
CVE-2023-51385
It was discovered that if an invalid user or hostname that contained
shell metacharacters was passed to ssh, and a ProxyCommand,
LocalCommand directive or “match exec” predicate referenced the user
or hostname via expansion tokens, then an attacker who could supply
arbitrary user/hostnames to ssh could potentially perform command
injection. The situation could arise in case of git repositories
with submodules, where the repository could contain a submodule with
shell characters in its user or hostname.
More Stories
rpki-client-9.5-1.el10_0
FEDORA-EPEL-2025-2ec16b3a94 Packages in this update: rpki-client-9.5-1.el10_0 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....
rpki-client-9.5-1.fc41
FEDORA-2025-17fed14cc3 Packages in this update: rpki-client-9.5-1.fc41 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....
rpki-client-9.5-1.fc40
FEDORA-2025-d5fdbedb7f Packages in this update: rpki-client-9.5-1.fc40 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....
rpki-client-9.5-1.el9
FEDORA-EPEL-2025-f8a9a83d41 Packages in this update: rpki-client-9.5-1.el9 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....
rpki-client-9.5-1.el10_1
FEDORA-EPEL-2025-f8fbd7b9af Packages in this update: rpki-client-9.5-1.el10_1 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....
rpki-client-9.5-1.fc42
FEDORA-2025-3887603605 Packages in this update: rpki-client-9.5-1.fc42 Update description: rpki-client 9.5 rpki-client now includes arin.tal which is no longer legally encumbered....