Bugzilla – Bug 1209420
VUL-0: CVE-2023-28531: openssh: ssh-add adds smartcard keys to ssh-agent without the intended per-hop destination constraints.
Last modified: 2024-07-04 09:46:40 UTC
CVE-2023-28531 ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-28531 https://www.cve.org/CVERecord?id=CVE-2023-28531 http://www.openwall.com/lists/oss-security/2023/03/15/8
only relevant for openSUSE:Factory as the 8.9 is shipped there: > ssh-add(1): when adding smartcard keys to ssh-agent(1) with the > per-hop desination constraints (ssh-add -h ...) added in OpenSSH > 8.9, a logic error prevented the constraints from being > communicated to the agent. This resulted in the keys being added > without constraints. The common cases of non-smartcard keys and > keys without destination constraints are unaffected. This problem > was reported by Luci Stanescu.
is fixed in factory i think