CVE-2023-51767

Name
CVE-2023-51767
Description
OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. NOTE: this is disputed by the Supplier, who states "we do not consider it to be the application's responsibility to defend against platform architectural weaknesses."
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://arxiv.org/abs/2309.02545
cve@mitre.org https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77
cve@mitre.org https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878
cve@mitre.org https://access.redhat.com/security/cve/CVE-2023-51767
cve@mitre.org https://bugzilla.redhat.com/show_bug.cgi?id=2255850
cve@mitre.org https://ubuntu.com/security/CVE-2023-51767
cve@mitre.org https://security.netapp.com/advisory/ntap-20240125-0006/
cve@mitre.org https://www.openwall.com/lists/oss-security/2025/09/22/1
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/22/1
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/22/2
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/23/4
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/24/4
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/10/01/1
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/10/01/2
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/23/1
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/23/3
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/23/5
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/24/7
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/25/2
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/25/6
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/26/2
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/26/4
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/27/1
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/27/2
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/27/3
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/27/5
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/27/6
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/27/7
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/29/4
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/29/5
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/29/6
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/27/4
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/28/7
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/09/29/1

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:openssh:openssh:*:*:*:*:*:*:*:* openssh >= None <= 9.6
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* openssh == None == None

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
openssh edge-main 10.2_p1-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 10.1_p1-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 10.0_p1-r11 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 10.0_p1-r10 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 10.0_p1-r9 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 10.0_p1-r8 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 10.0_p1-r7 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 10.0_p1-r6 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 10.0_p1-r5 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 10.0_p1-r4 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 10.0_p1-r3 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 10.0_p1-r2 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 10.0_p1-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 9.9_p2-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 9.9_p1-r2 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 9.8_p1-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh edge-main 9.6_p1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openssh edge-main 8.9_p2-r0 None possibly vulnerable
openssh edge-main 8.8_p1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openssh edge-main 8.5_p1-r0 None possibly vulnerable
openssh edge-main 8.4_p1-r0 None possibly vulnerable
openssh edge-main 7.9_p1-r3 None possibly vulnerable
openssh edge-main 7.7_p1-r4 None possibly vulnerable
openssh edge-main 7.5_p1-r8 None possibly vulnerable
openssh edge-main 7.4_p1-r0 None possibly vulnerable
openssh 3.23-main 10.2_p1-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh 3.22-main 10.0_p1-r10 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh 3.22-main 10.0_p1-r9 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh 3.22-main 10.0_p1-r8 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh 3.22-main 10.0_p1-r7 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh 3.22-main 9.9_p2-r0 None fixed
openssh 3.22-main 9.8_p1-r0 None fixed
openssh 3.22-main 9.6_p1-r0 None possibly vulnerable
openssh 3.22-main 8.8_p1-r0 None possibly vulnerable
openssh 3.22-main 8.5_p1-r0 None possibly vulnerable
openssh 3.22-main 8.4_p1-r0 None possibly vulnerable
openssh 3.22-main 7.9_p1-r3 None possibly vulnerable
openssh 3.22-main 7.7_p1-r4 None possibly vulnerable
openssh 3.22-main 7.5_p1-r8 None possibly vulnerable
openssh 3.22-main 7.4_p1-r0 None possibly vulnerable
openssh 3.21-main 9.9_p2-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh 3.21-main 9.9_p1-r2 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh 3.21-main 9.8_p1-r0 None fixed
openssh 3.21-main 9.6_p1-r0 None possibly vulnerable
openssh 3.21-main 8.8_p1-r0 None possibly vulnerable
openssh 3.21-main 8.5_p1-r0 None possibly vulnerable
openssh 3.21-main 8.4_p1-r0 None possibly vulnerable
openssh 3.21-main 7.9_p1-r3 None possibly vulnerable
openssh 3.21-main 7.7_p1-r4 None possibly vulnerable
openssh 3.21-main 7.5_p1-r8 None possibly vulnerable
openssh 3.21-main 7.4_p1-r0 None possibly vulnerable
openssh 3.20-main 9.7_p1-r5 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh 3.20-main 9.7_p1-r4 Natanael Copa <ncopa@alpinelinux.org> fixed
openssh 3.20-main 9.6_p1-r0 None possibly vulnerable
openssh 3.20-main 8.8_p1-r0 None possibly vulnerable
openssh 3.20-main 8.5_p1-r0 None possibly vulnerable
openssh 3.20-main 8.4_p1-r0 None possibly vulnerable
openssh 3.20-main 7.9_p1-r3 None possibly vulnerable
openssh 3.20-main 7.7_p1-r4 None possibly vulnerable
openssh 3.20-main 7.5_p1-r8 None possibly vulnerable
openssh 3.20-main 7.4_p1-r0 None possibly vulnerable
openssh 3.19-main 9.7_p2-r5 None fixed
openssh 3.19-main 9.6_p1-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openssh 3.19-main 9.6_p1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openssh 3.19-main 9.6_p1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openssh 3.19-main 8.8_p1-r0 None possibly vulnerable
openssh 3.19-main 8.5_p1-r0 None possibly vulnerable
openssh 3.19-main 8.4_p1-r0 None possibly vulnerable
openssh 3.19-main 7.9_p1-r3 None possibly vulnerable
openssh 3.19-main 7.7_p1-r4 None possibly vulnerable
openssh 3.19-main 7.5_p1-r8 None possibly vulnerable
openssh 3.19-main 7.4_p1-r0 None possibly vulnerable
openssh 3.18-main 9.3_p2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openssh 3.18-main 9.3_p2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openssh 3.17-main 9.1_p1-r6 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openssh 3.17-main 9.1_p1-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
openssh 3.17-main 9.1_p1-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable