Untrusted search path in OpenSSH - CVE-2023-38408
Published: July 20, 2023 / Updated: January 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to usage of an insecure search path within the PKCS#11 feature in ssh-agent. A remote attacker can trick the victim into connecting to a malicious SSH server and execute arbitrary code on the system, if an agent is forwarded to an attacker-controlled system.
Note, this vulnerability exists due to incomplete fix for #VU2015 (CVE-2016-10009).
Affected software
IBM Security Verify Access
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
CentOS
Anolis OS
SUSE Enterprise Storage
IBM i
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server 12 SP2 BCL
FreeBSD
Ubuntu
Slackware Linux
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Fedora
macOS
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Cloud Pak for Network Automation
Oracle Enterprise Communications Broker
Platform Automation Toolkit
Verify Identity Access Digital Credentials
Oracle Communications Policy Management
ObjectScale
IBM Cloud Pak for Watson AIOps
Enterprise SONiC
XtremIO X2
Storage Protect Plus Container Agent
EMC Cloud Tiering Appliance
IBM Security Guardium
VolSync
OpenShift Pipelines
IBM Spectrum Copy Data Management
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
VMware Tanzu Application Service for VMs
Isolation Segment
Oracle VM Server for x86
Red Hat Migration Toolkit for Applications
Oracle Communications Diameter Signaling Router
Oracle Communications Cloud Native Core Binding Support Function
DevWorkspace Operator
Session Smart Router
IBM Security Verify Governance
Juniper Cloud Native Router
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Oracle Enterprise Operations Monitor
Multicluster Engine for Kubernetes
VMware Tanzu Operations Manager
OpenShift Virtualization
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
openssh-client (Ubuntu package)
pam_ssh_agent_auth
openssh (Red Hat package)
openssh-helpers
openssh-debugsource
openssh-helpers-debuginfo
openssh-fips
openssh-askpass-gnome-debuginfo
openssh-debuginfo
openssh-askpass-gnome
openssh
openssh-askpass
openssh-server
openssh-ldap
openssh-keycat
openssh-clients
openssh-cavs
openssh-server-sysvinit
openssh-askpass-gnome-debugsource
openssh-common-debuginfo
openssh-cavs-debuginfo
openssh-clients-debuginfo
openssh-common
openssh-server-debuginfo
openssh-doc
QuTS hero
Junos cRPD
IBM Data Risk Manager
IBM QRadar Network Packet Capture
IBM Integrated Analytics System
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
QNAP QTS
RecoverPoint for VMs
Dell EMC VxRail Appliance
RSA Authentication Manager
How to mitigate CVE-2023-38408
VolSync - addressed in versions 0.5.4, 0.6.3
Migration Toolkit for Containers - update to 1.7.12
OpenShift Pipelines - update to 1.10.6
Multicluster Engine for Kubernetes - addressed in versions 2.1.8, 2.2.7
IBM Spectrum Copy Data Management - update to 2.2.21.0
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.7.7, 2.8.1
VMware Tanzu Operations Manager - update to 2.10.61
VMware Tanzu Application Service for VMs - addressed in versions 2.11.44, 2.13.26, 3.0.16, 4.0.8
Isolation Segment - addressed in versions 2.11.38, 2.13.23, 3.0.16, 4.0.8
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
OpenShift Virtualization - update to 4.11.6
Red Hat OpenShift Container Platform - update to 4.13.8
Red Hat Migration Toolkit for Applications - update to 6.2.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
openssh-client (Ubuntu package) - addressed in versions Ubuntu Pro, 1:8.2p1-4ubuntu0.8, 1:8.9p1-3ubuntu0.3, 1:9.0p1-1ubuntu8.4
QuTS hero - update to h5.1.8.2823 build 20240712
pam_ssh_agent_auth - addressed in versions 0.10.3-2.23, 0.10.3-7.18.0.1, 0.10.4-7.9
pam_ssh_agent_auth - update to 0.10.3-9.27
DevWorkspace Operator - update to 0.22
ObjectScale - update to 1.4.0
IBM Data Risk Manager - update to 2.0.6.20
IBM Cloud Pak for Watson AIOps - update to 4.1.2
Enterprise SONiC - update to 4.1.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
EMC ViPR SRM - update to 4.10.0.0
QNAP QTS - update to 5.1.8.2823 20240712
openssh (Red Hat package) - addressed in versions 5.3p1-125.el6_10, 7.4p1-23.el7_9, 8.0p1-5.el8_1.1, 8.0p1-5.el8_2, 8.0p1-7.el8_4, 8.0p1-15.el8_6, 8.0p1-19.el8_8, 8.7p1-11.el9_0, 8.7p1-30.el9_2
RecoverPoint for VMs - update to 6.0.SP1.P1
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
XtremIO X2 - update to 6.4.2-13
openssh-helpers - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-debugsource - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-helpers-debuginfo - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-fips - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-askpass-gnome-debuginfo - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-debuginfo - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-askpass-gnome - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-askpass - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-server - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-ldap - addressed in versions 7.4p1-23, 8.0p1-18.0.1
openssh-keycat - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-clients - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-cavs - addressed in versions 7.4p1-23, 8.0p1-18.0.1
openssh-server-sysvinit - update to 7.4p1-23
openssh - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 6
openssh-askpass-gnome-debugsource - addressed in versions 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
IBM Integrated Analytics System - update to 7.9.23.08.SP21
Dell EMC VxRail Appliance - update to 8.0.120
openssh-common-debuginfo - update to 8.4p1-150300.3.22.1
openssh-cavs - update to 8.4p1-150300.3.22.1
openssh-cavs-debuginfo - update to 8.4p1-150300.3.22.1
openssh-clients-debuginfo - update to 8.4p1-150300.3.22.1
openssh-common - update to 8.4p1-150300.3.22.1
openssh-server - update to 8.4p1-150300.3.22.1
openssh-clients - update to 8.4p1-150300.3.22.1
openssh-server-debuginfo - update to 8.4p1-150300.3.22.1
RSA Authentication Manager - addressed in versions 8.7 SP1 Patch 3, 8.7 SP2 Patch 1
openssh - addressed in versions 8.8p1-11.fc37, 9.0p1-16.fc38
openssh-doc - update to 9.0p1-9
openssh - update to 9.3p2
IBM Security Verify Governance - update to 10.0.2.0.4
Storage Protect Plus Container Agent - update to 10.1.15.3
EMC Cloud Tiering Appliance - update to 13.2.0.2.24
macOS - update to 14.0 23A344
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
Links to Public Exploits and PoC-codes
- Exploit #12268 - CVE-2023-38408 (CVE-2023-38408 SSH Vulnerability Scanner & PoC) (January 9, 2026)
- Exploit #10206 - CVE-2023-38408 (CVE-2023-38408 Remote Code Execution in OpenSSH's forwarded ssh-agent) (July 12, 2024)
- Exploit #9660 - CVE-2023-38408 (Takeover Account OpenSSH) (April 5, 2024)
- Exploit #9630 - CVE-2023-38408 (PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2) (March 22, 2024)
External References
- https://github.com/openbsd/src/commit/7bc29a9d5cd697290aa056e94ecee6253d3425f8
- https://www.openssh.com/txt/release-9.3p2
- https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt
- https://blog.qualys.com/vulnerabilities-threat-research/2023/07/19/cve-2023-38408-remote-code-execution-in-opensshs-forwarded-ssh-agent
- https://news.ycombinator.com/item?id=36790196
- https://github.com/openbsd/src/commit/f8f5a6b003981bb824329dc987d101977beda7ca
- https://github.com/openbsd/src/commit/f03a4faa55c4ce0818324701dadbf91988d7351d
- https://www.openssh.com/security.html
- https://security.gentoo.org/glsa/202307-01
Related Security Bulletins
- Remote code execution in OpenSSH ssh-agent
- Gentoo update for OpenSSH
- Slackware Linux update for openssh
- SUSE update for openssh
- SUSE update for openssh
- SUSE update for openssh
- SUSE update for openssh
- SUSE update for openssh
- Ubuntu update for openssh
- Red Hat Enterprise Linux 9.0 Extended Update Support update for openssh
- Ubuntu update for openssh
- Red Hat Enterprise Linux 8 update for openssh
- Red Hat Enterprise Linux 7 update for openssh
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for openssh
- Red Hat Enterprise Linux 8 update for openssh
- Red Hat Enterprise Linux 9 update for openssh
- Red Hat Enterprise Linux 8.6 Extended Update Support update for openssh
- Red Hat Enterprise Linux 8 update for openssh
- FreeBSD update for ssh-agent
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for openssh
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat VolSync 0.6
- Multiple vulnerabilities in Red Hat VolSync 0.5
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.2
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.7
- Fedora 37 update for openssh
- Fedora 38 update for openssh
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Amazon Linux AMI update for openssh
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.8
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Red Hat DevWorkspace Operator update for openssh
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.1
- Multiple vulnerabilities in IBM i
- Untrusted search path in IBM Integrated Analytics System
- Multiple Vulnerabilities in IBM CloudPak for Watson AIOps
- Multiple vulnerabilities in Red Hat OpenShift Virtualization release 4.11
- Multiple vulnerabilities in IBM Spectrum Copy Data Management
- Multiple vulnerabilities in Oracle VM Server for x86
- Untrusted search path in IBM Security Guardium
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Oracle Enterprise Operations Monitor
- Multiple vulnerabilities in Oracle Communications Policy Management
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- VMware Tanzu update for OpenSSH
- Multiple vulnerabilities in Migration Toolkit for Applications 6.2
- Multiple vulnerabilities in IBM Storage Protect Plus
- Multiple vulnerabilities in Migration Toolkit for Virtualization 2.4
- Multiple vulnerabilities in Dell EMC Enterprise SONiC
- Multiple vulnerabilities in Red Hat OpenShift Pipelines 1.10
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- CentOS 7 update for openssh
- Multiple vulnerabilities in IBM Data Risk Manager
- openEuler update for openssh
- Multiple vulnerabilities in Juniper Cloud Native Router
- Multiple vulnerabilities in Juniper Networks Junos cRPD
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Multiple vulnerabilities in Oracle Enterprise Communications Broker
- Multiple vulnerabilities in QNAP QTS and QuTS hero
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Multiple vulnerabilities in Dell XtremIO X2
- Amazon Linux AMI update for openssh
- Anolis OS update for openssh
- Anolis OS update for openssh
- Anolis OS update for openssh
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in IBM Verify Identity Access and IBM Security Verify Access
- Juniper Session Smart Router update for third-party components