Bugzilla – Bug 1218134
VUL-0: CVE-2023-48795: jsch: prefix truncation breaking ssh channel integrity
Last modified: 2024-02-05 16:30:12 UTC
chacha20-poly1305 was added in jsch 0.1.66. MAC etms were added in jsch 0.1.58. currently not yet shipped for SLES, but already in the QA queue.
terrapin attack is now public https://terrapin-attack.com/
jsch-0.2.15 is being prepared with the fixes (tagged already, release is not yet there). We should just update to that. https://github.com/mwiede/jsch/releases
This is an autogenerated message for OBS integration: This bug (1218134) was mentioned in https://build.opensuse.org/request/show/1138302 Factory / jsch
Upgraded jsch to version 0.2.15, and dependency bouncycastle to 1.77 in SLE and ALP
SUSE-SU-2024:0327-1: An update that solves one vulnerability can now be installed. Category: security (important) Bug References: 1218134 CVE References: CVE-2023-48795 Sources used: SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 SUSE Linux Enterprise Server for SAP Applications 15 SP4 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 SUSE Enterprise Storage 7.1 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 openSUSE Leap 15.5 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 Development Tools Module 15-SP5 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 SUSE Manager Server 4.3 Module 4.3 (src): jsch-0.2.15-150200.11.13.1 SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src): jsch-0.2.15-150200.11.13.1, bouncycastle-1.77-150200.3.24.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.