FlawAtlas
Search the atlas
UBUNTU-CVE-2023-51384 Moderate

UBUNTU-CVE-2023-51384

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

Exploit probability Not scored
Published December 20, 2023
Required by Not available
Last source change May 29, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:18.04:LTS openssh-ssh1

4 explicit affected versions

Ubuntu:20.04:LTS openssh-ssh1

1 explicit affected versions

Ubuntu:22.04:LTS openssh

10 explicit affected versions

Ubuntu:22.04:LTS openssh-ssh1

3 explicit affected versions

Ubuntu:24.04:LTS openssh

2 explicit affected versions

Ubuntu:24.04:LTS openssh-ssh1

4 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2023-51384

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

View original source

05 / REFERENCES

Further evidence