{"id":"CVE-2023-38408","details":"The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.","modified":"2026-07-22T02:25:27.691969Z","published":"2023-07-20T00:00:00Z","related":["ALSA-2023:4412","ALSA-2023:4419","CGA-frmw-hj73-jq63","SUSE-SU-2023:2940-1","SUSE-SU-2023:2945-1","SUSE-SU-2023:2946-1","SUSE-SU-2023:2947-1","SUSE-SU-2023:2950-1","openSUSE-SU-2024:13063-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"9.3p2"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38408.json"},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/173661/OpenSSH-Forwarded-SSH-Agent-Remote-Code-Execution.html"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=36790196"},{"type":"WEB","url":"https://support.apple.com/kb/HT213940"},{"type":"WEB","url":"https://www.openssh.com/security.html"},{"type":"WEB","url":"https://www.openssh.com/txt/release-9.3p2"},{"type":"WEB","url":"https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/exploring-opensshs-agent-forwarding-rce-cve-2023-38408"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38408.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CEBTJJINE2I3FHAUKKNQWMFGYMLSMWKQ/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RAXVQS6ZYTULFAK3TEJHRLKZALJS3AOU/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38408"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202307-01"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230803-0010/"},{"type":"FIX","url":"https://github.com/openbsd/src/commit/7bc29a9d5cd697290aa056e94ecee6253d3425f8"},{"type":"FIX","url":"https://github.com/openbsd/src/commit/f03a4faa55c4ce0818324701dadbf91988d7351d"},{"type":"FIX","url":"https://github.com/openbsd/src/commit/f8f5a6b003981bb824329dc987d101977beda7ca"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/07/20/1"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/07/20/2"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/09/22/11"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2023/09/22/9"},{"type":"ARTICLE","url":"https://blog.qualys.com/vulnerabilities-threat-research/2023/07/19/cve-2023-38408-remote-code-execution-in-opensshs-forwarded-ssh-agent"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00021.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openbsd/src","events":[{"introduced":"0"},{"fixed":"7bc29a9d5cd697290aa056e94ecee6253d3425f8"},{"fixed":"f03a4faa55c4ce0818324701dadbf91988d7351d"},{"fixed":"f8f5a6b003981bb824329dc987d101977beda7ca"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-38408.json","vanir_signatures_modified":"2026-07-22T02:25:27Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/openbsd/src/commit/f8f5a6b003981bb824329dc987d101977beda7ca","target":{"file":"usr.bin/ssh/misc.h"},"deprecated":false,"digest":{"line_hashes":["245460714767665081683172703272227756490","154898809948973226043331289679083724583","77397090139273800238042145169749086301","190441682610337999482858680156181833541","61249771291454899113495469699607840047"],"threshold":0.9},"id":"CVE-2023-38408-1b7fe2ad","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["212889176108583557153764785879829373553","199957646585614272140038170333640429763","104255286907295786427889062166350281187","115009805797771706544464707642295063611","129285339640906578826404216174930229758","293458422494043100795111688876212186380","158184544829091383528505314573683842298","141142978561658504241622758231208165624","261354179858232412412223785435861205101","272211793939171938655602293807909585244","26312110325341625339236976058409048896","37222675372245245516667306127403666209","231893991694577093191465781901120692399","208944525142893471893429544502409167621"],"threshold":0.9},"id":"CVE-2023-38408-38072bcc","signature_type":"Line","signature_version":"v1","source":"https://github.com/openbsd/src/commit/f8f5a6b003981bb824329dc987d101977beda7ca","target":{"file":"usr.bin/ssh/ssh-sk.c"}},{"source":"https://github.com/openbsd/src/commit/f8f5a6b003981bb824329dc987d101977beda7ca","target":{"file":"usr.bin/ssh/misc.c"},"deprecated":false,"digest":{"line_hashes":["123728030011908799690508130257531630145","309320613159800543722057427906030885293","88551071913815231098859714061627564583","255716208541812258235985042308243123018","327713260949006026913669588332977405706","195026673253470011006274772763615138419"],"threshold":0.9},"id":"CVE-2023-38408-477a87a4","signature_type":"Line","signature_version":"v1"},{"target":{"file":"usr.bin/ssh/ssh-pkcs11.c"},"deprecated":false,"digest":{"line_hashes":["55725163042805392808609753741105633240","132403242283107965528557055591865070823","145711729613275442506525195537586480099","81698505837951782601199886233863780510","164975228933773000300492059888318553713","203760564816490794400113698258768785600","87744079937004542252727256443966031343","233201331787054679358425020029285230149"],"threshold":0.9},"id":"CVE-2023-38408-4c8fc60e","signature_type":"Line","signature_version":"v1","source":"https://github.com/openbsd/src/commit/f03a4faa55c4ce0818324701dadbf91988d7351d"},{"signature_version":"v1","source":"https://github.com/openbsd/src/commit/7bc29a9d5cd697290aa056e94ecee6253d3425f8","target":{"file":"usr.bin/ssh/ssh-agent.c","function":"process_add_smartcard_key"},"deprecated":false,"digest":{"function_hash":"176282625954728589418260577592136122934","length":1790},"id":"CVE-2023-38408-548fc75b","signature_type":"Function"},{"id":"CVE-2023-38408-63a621a6","signature_type":"Line","signature_version":"v1","source":"https://github.com/openbsd/src/commit/7bc29a9d5cd697290aa056e94ecee6253d3425f8","target":{"file":"usr.bin/ssh/ssh-agent.c"},"deprecated":false,"digest":{"line_hashes":["142483365029668147691457446802921276205","338183608448739778899193325290408274327","215742378688413246027441518061584069043","34199311701557504296485376417782017829","264814179936733595673977523540311910896","48107387833747494942141378138305335526","311430354134093433623203190391857462306","322112388604258461414191286219043701982","187077904320853389933675193085424106859","119536953480021437428967222865166673018","300272016207263626724188131418314932382","185434096474314764300222071171674739821","242914950751014010650316723974235697586","111874031984715289587838461750616793356","314524614974619895120979930351770212331","207219957535858364281635286727481124690"],"threshold":0.9}},{"deprecated":false,"digest":{"function_hash":"69408485039866777726565847449831891868","length":5787},"id":"CVE-2023-38408-65d1ca36","signature_type":"Function","signature_version":"v1","source":"https://github.com/openbsd/src/commit/7bc29a9d5cd697290aa056e94ecee6253d3425f8","target":{"file":"usr.bin/ssh/ssh-agent.c","function":"main"}},{"digest":{"function_hash":"86622299653523171526230085861346440775","length":1945},"id":"CVE-2023-38408-b20aa0ae","signature_type":"Function","signature_version":"v1","source":"https://github.com/openbsd/src/commit/f8f5a6b003981bb824329dc987d101977beda7ca","target":{"file":"usr.bin/ssh/ssh-sk.c","function":"sshsk_open"},"deprecated":false},{"digest":{"function_hash":"263025605123250630080940306656039656526","length":2430},"id":"CVE-2023-38408-d35307ad","signature_type":"Function","signature_version":"v1","source":"https://github.com/openbsd/src/commit/7bc29a9d5cd697290aa056e94ecee6253d3425f8","target":{"file":"usr.bin/ssh/ssh-agent.c","function":"process_add_identity"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/openbsd/src/commit/f03a4faa55c4ce0818324701dadbf91988d7351d","target":{"file":"usr.bin/ssh/ssh-pkcs11.c","function":"pkcs11_register_provider"},"deprecated":false,"digest":{"function_hash":"157551009127729258625712862157649782138","length":4424},"id":"CVE-2023-38408-e2f7b684"}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/openssh/openssh-portable","events":[{"introduced":"cb30fbdbee869f1ce11f06aa97e1cb8717a0b645"},{"last_affected":"cb30fbdbee869f1ce11f06aa97e1cb8717a0b645"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:openbsd:openssh:9.3:p1:*:*:*:*:*:*","extracted_events":[{"introduced":"9.3-p1"},{"last_affected":"9.3-p1"}]}}],"versions":["9.3-p1","V_9_3_P1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-38408.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}