Bugzilla – Bug 1218214
VUL-0: CVE-2023-51384: openssh: incomplete constraints during addition of PKCS#11-hosted private keys
Last modified: 2024-05-21 09:08:00 UTC
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-51384
also ALP is affected submit to: SUSE:ALP:Source:Standard:1.0 openssh
as the feature was only added in recent openssh versions, the security problem does not apply to earlier versions than 9.3p1