CVE-2023-51767 The advisory has been revoked - it doesn't affect any version of package openssh Open this link in a new tab
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UBUNTU1404-OPENSSH-6142093
- published 3 Jan 2024
- disclosed 24 Dec 2023
Introduced: 24 Dec 2023
CVE-2023-51767 Open this link in a new tabAmendment
The Ubuntu
security team deemed this advisory irrelevant for Ubuntu:14.04
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream openssh
package and not the openssh
package as distributed by Ubuntu
.
OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.
References
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2023-51767
- https://arxiv.org/abs/2309.02545
- https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77
- https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878
- https://access.redhat.com/security/cve/CVE-2023-51767
- https://bugzilla.redhat.com/show_bug.cgi?id=2255850
- https://ubuntu.com/security/CVE-2023-51767
- https://security.netapp.com/advisory/ntap-20240125-0006/