Security controls bypass or absence In openssh
Description
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 1:9.2p1-2+deb12u10 | ||
rpm rhel8 | 0:8.0p1-29.el8_10 | ||
rpm rhel9 | 0:9.9p1-7.el9_8 | ||
rpm rhel10 | 0:9.9p1-23.el10_2 | ||
rpm rhel6 | - | - | |
debian 14 | 1:10.3p1-1 | ||
debian 11 | 1:8.4p1-5+deb11u7 | ||
debian 13 | 1:10.0p1-7+deb13u3 | ||
rpm rhel7 | - | - | |
rpm rhel10.0 | 0:9.9p1-7.el10_0.3 |
1-10 of 13
10
Aliases
1. 2. 3. 4. 5.