Lucene search

K
oraclelinuxOracleLinuxELSA-2023-4382
HistoryAug 02, 2023 - 12:00 a.m.

openssh security update

2023-08-0200:00:00
linux.oracle.com
110
openssh version 7.4p1
security update
buffer size enlargement
remote code execution
pkcs#11 support
cve-2023-38408
unix

0.028 Low

EPSS

Percentile

90.6%

[7.4p1-23.0.1]

  • enlarge format buffer size for certificate serial
    number so the log message can record any 64-bit integer without
    truncation (openssh bz#3012) [Orabug: 30448895]
    [7.4p1-23 + 0.10.3-2]
  • Avoid remote code execution in ssh-agent PKCS#11 support
    Resolves: CVE-2023-38408