Untrusted search path in OpenSSH - CVE-2023-38408

 

Untrusted search path in OpenSSH - CVE-2023-38408

Published: July 20, 2023 / Updated: January 9, 2026


Vulnerability identifier: #VU78454
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38408
CWE-ID: CWE-426
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to usage of an insecure search path within the PKCS#11 feature in ssh-agent. A remote attacker can trick the victim into connecting to a malicious SSH server and execute arbitrary code on the system, if an agent is forwarded to an attacker-controlled system.

Note, this vulnerability exists due to incomplete fix for #VU2015 (CVE-2016-10009).


Affected software

OpenSSH
IBM Security Verify Access
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
CentOS
Anolis OS
SUSE Enterprise Storage
IBM i
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server 12 SP2 BCL
FreeBSD
Ubuntu
Slackware Linux
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Fedora
macOS
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Cloud Pak for Network Automation
Oracle Enterprise Communications Broker
Platform Automation Toolkit
Verify Identity Access Digital Credentials
Oracle Communications Policy Management
ObjectScale
IBM Cloud Pak for Watson AIOps
Enterprise SONiC
XtremIO X2
Storage Protect Plus Container Agent
EMC Cloud Tiering Appliance
IBM Security Guardium
VolSync
OpenShift Pipelines
IBM Spectrum Copy Data Management
Migration Toolkit for Virtualization
Red Hat Advanced Cluster Management for Kubernetes
VMware Tanzu Application Service for VMs
Isolation Segment
Oracle VM Server for x86
Red Hat Migration Toolkit for Applications
Oracle Communications Diameter Signaling Router
Oracle Communications Cloud Native Core Binding Support Function
DevWorkspace Operator
Session Smart Router
IBM Security Verify Governance
Juniper Cloud Native Router
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Oracle Enterprise Operations Monitor
Multicluster Engine for Kubernetes
VMware Tanzu Operations Manager
OpenShift Virtualization
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
openssh-client (Ubuntu package)
pam_ssh_agent_auth
openssh (Red Hat package)
openssh-helpers
openssh-debugsource
openssh-helpers-debuginfo
openssh-fips
openssh-askpass-gnome-debuginfo
openssh-debuginfo
openssh-askpass-gnome
openssh
openssh-askpass
openssh-server
openssh-ldap
openssh-keycat
openssh-clients
openssh-cavs
openssh-server-sysvinit
openssh-askpass-gnome-debugsource
openssh-common-debuginfo
openssh-cavs-debuginfo
openssh-clients-debuginfo
openssh-common
openssh-server-debuginfo
openssh-doc
QuTS hero
Junos cRPD
IBM Data Risk Manager
IBM QRadar Network Packet Capture
IBM Integrated Analytics System
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
QNAP QTS
RecoverPoint for VMs
Dell EMC VxRail Appliance
RSA Authentication Manager

How to mitigate CVE-2023-38408

Install updates from vendor's website.

OpenSSH - update to 9.3p2
VolSync - addressed in versions 0.5.4, 0.6.3
Migration Toolkit for Containers - update to 1.7.12
OpenShift Pipelines - update to 1.10.6
Multicluster Engine for Kubernetes - addressed in versions 2.1.8, 2.2.7
IBM Spectrum Copy Data Management - update to 2.2.21.0
Migration Toolkit for Virtualization - update to 2.4.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.7.7, 2.8.1
VMware Tanzu Operations Manager - update to 2.10.61
VMware Tanzu Application Service for VMs - addressed in versions 2.11.44, 2.13.26, 3.0.16, 4.0.8
Isolation Segment - addressed in versions 2.11.38, 2.13.23, 3.0.16, 4.0.8
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
OpenShift Virtualization - update to 4.11.6
Red Hat OpenShift Container Platform - update to 4.13.8
Red Hat Migration Toolkit for Applications - update to 6.2.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
openssh-client (Ubuntu package) - addressed in versions Ubuntu Pro, 1:8.2p1-4ubuntu0.8, 1:8.9p1-3ubuntu0.3, 1:9.0p1-1ubuntu8.4
QuTS hero - update to h5.1.8.2823 build 20240712
pam_ssh_agent_auth - addressed in versions 0.10.3-2.23, 0.10.3-7.18.0.1, 0.10.4-7.9
pam_ssh_agent_auth - update to 0.10.3-9.27
DevWorkspace Operator - update to 0.22
ObjectScale - update to 1.4.0
IBM Data Risk Manager - update to 2.0.6.20
IBM Cloud Pak for Watson AIOps - update to 4.1.2
Enterprise SONiC - update to 4.1.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
EMC ViPR SRM - update to 4.10.0.0
QNAP QTS - update to 5.1.8.2823 20240712
openssh (Red Hat package) - addressed in versions 5.3p1-125.el6_10, 7.4p1-23.el7_9, 8.0p1-5.el8_1.1, 8.0p1-5.el8_2, 8.0p1-7.el8_4, 8.0p1-15.el8_6, 8.0p1-19.el8_8, 8.7p1-11.el9_0, 8.7p1-30.el9_2
RecoverPoint for VMs - update to 6.0.SP1.P1
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
XtremIO X2 - update to 6.4.2-13
openssh-helpers - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-debugsource - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-helpers-debuginfo - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-fips - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-askpass-gnome-debuginfo - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-debuginfo - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-askpass-gnome - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh - addressed in versions 7.2p2-74.63.1, 7.2p2-81.4.2, 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
openssh-askpass - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-server - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-ldap - addressed in versions 7.4p1-23, 8.0p1-18.0.1
openssh-keycat - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-clients - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
openssh-cavs - addressed in versions 7.4p1-23, 8.0p1-18.0.1
openssh-server-sysvinit - update to 7.4p1-23
openssh - addressed in versions 7.4p1-23, 8.0p1-18.0.1, 9.0p1-9
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 6
openssh-askpass-gnome-debugsource - addressed in versions 7.9p1-150100.6.31.1, 8.1p1-150200.5.37.1, 8.4p1-150300.3.22.1
IBM Integrated Analytics System - update to 7.9.23.08.SP21
Dell EMC VxRail Appliance - update to 8.0.120
openssh-common-debuginfo - update to 8.4p1-150300.3.22.1
openssh-cavs - update to 8.4p1-150300.3.22.1
openssh-cavs-debuginfo - update to 8.4p1-150300.3.22.1
openssh-clients-debuginfo - update to 8.4p1-150300.3.22.1
openssh-common - update to 8.4p1-150300.3.22.1
openssh-server - update to 8.4p1-150300.3.22.1
openssh-clients - update to 8.4p1-150300.3.22.1
openssh-server-debuginfo - update to 8.4p1-150300.3.22.1
RSA Authentication Manager - addressed in versions 8.7 SP1 Patch 3, 8.7 SP2 Patch 1
openssh - addressed in versions 8.8p1-11.fc37, 9.0p1-16.fc38
openssh-doc - update to 9.0p1-9
openssh - update to 9.3p2
IBM Security Verify Governance - update to 10.0.2.0.4
Storage Protect Plus Container Agent - update to 10.1.15.3
EMC Cloud Tiering Appliance - update to 13.2.0.2.24
macOS - update to 14.0 23A344
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins