FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

FreeBSD -- ssh-add does not honor per-hop destination constraints

Affected packages
12.4 <= FreeBSD < 12.4_3

Details

VuXML ID e31a8f8e-47bf-11ee-8e38-002590c1f29c
Discovery 2023-06-21
Entry 2023-08-31

Problem Description:

When using ssh-add(1) to add smartcard keys to ssh-agent(1) with per-hop destination constraints, a logic error prevented the constraints from being sent to the agent resulting in keys being added to the agent without constraints.

Impact:

A malicious server could leverage the keys provided by a forwarded agent that would normally not be allowed due to the logic error.

References

CVE Name CVE-2023-28531
FreeBSD Advisory SA-23:05.openssh