Wind River Support Network

HomeDefectsLIN1021-6978
Acknowledged

LIN1021-6978 : Security Advisory - openssh - CVE-2023-51767

Created: Dec 25, 2023    Updated: Jan 12, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.

CREATE(Triage):(User=admin) CVE-2023-51767 (https://nvd.nist.gov/vuln/detail/CVE-2023-51767)
Live chat
Online