Executive brief
OpenSSH, a widely used tool for secure remote access, contains a flaw in how it handles smartcard security keys. When users attempt to apply specific security restrictions to these keys (limiting where they can be used), a logic error causes those restrictions to be ignored. This could allow a compromised intermediate server to use the security key in ways the user did not intend, potentially leading to unauthorized access across a network.
Technical details
A logic error exists in the 'ssh-add' utility of OpenSSH (versions 8.9 through 9.2) when handling smartcard keys via PKCS#11. When a user adds a smartcard key to 'ssh-agent' using the '-h' flag to specify destination constraints, the constraints are not properly communicated to the agent. Consequently, the keys are added to the agent with no restrictions, bypassing the intended security policy that limits key usage to specific network hops. This vulnerability is specific to smartcard/PKCS#11 keys; standard file-based keys are unaffected. The issue is resolved in OpenSSH 9.3.
Affected products
- OpenBSD OpenSSH 8.9 to 9.2
Timeline
- 2023-03-15: advisory: OpenSSH 9.3 released fixing the issue
- 2023-03-17: disclosed: NVD publication date
References
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AN2UDTXEUSKFIOIYMV6JNI5VSBMYZOFT/
- https://security.gentoo.org/glsa/202307-01
- https://security.netapp.com/advisory/ntap-20230413-0008/
- https://www.debian.org/security/2023/dsa-5586
- https://www.openwall.com/lists/oss-security/2023/03/15/8
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AN2UDTXEUSKFIOIYMV6JNI5VSBMYZOFT/
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html