{"schema_version":"1.7.5","id":"UBUNTU-CVE-2023-51384","published":"2023-12-20T00:00:00Z","modified":"2026-05-29T18:00:22.708627066Z","related":["USN-6565-1"],"upstream":["CVE-2023-51384"],"details":"In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.","affected":[{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-8","1:7.5p1-9","1:7.5p1-9build1","1:7.5p1-10"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client-ssh1","binary_version":"1:7.5p1-10"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-51384.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-11build1"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client-ssh1","binary_version":"1:7.5p1-11build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-51384.json"}},{"package":{"name":"openssh","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/openssh?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:8.9p1-3ubuntu0.6"}]}],"versions":["1:8.4p1-6ubuntu2","1:8.7p1-2","1:8.7p1-2build1","1:8.7p1-4","1:8.8p1-1","1:8.9p1-3","1:8.9p1-3ubuntu0.1","1:8.9p1-3ubuntu0.3","1:8.9p1-3ubuntu0.4","1:8.9p1-3ubuntu0.5"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"openssh-client","binary_version":"1:8.9p1-3ubuntu0.6"},{"binary_name":"openssh-server","binary_version":"1:8.9p1-3ubuntu0.6"},{"binary_name":"openssh-sftp-server","binary_version":"1:8.9p1-3ubuntu0.6"},{"binary_name":"openssh-tests","binary_version":"1:8.9p1-3ubuntu0.6"},{"binary_name":"ssh","binary_version":"1:8.9p1-3ubuntu0.6"},{"binary_name":"ssh-askpass-gnome","binary_version":"1:8.9p1-3ubuntu0.6"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-51384.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-12","1:7.5p1-12build1","1:7.5p1-13"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client-ssh1","binary_version":"1:7.5p1-13"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-51384.json"}},{"package":{"name":"openssh","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/openssh?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:9.6p1-3ubuntu1"}]}],"versions":["1:9.3p1-1ubuntu3","1:9.4p1-1ubuntu1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"openssh-client","binary_version":"1:9.6p1-3ubuntu1"},{"binary_name":"openssh-server","binary_version":"1:9.6p1-3ubuntu1"},{"binary_name":"openssh-sftp-server","binary_version":"1:9.6p1-3ubuntu1"},{"binary_name":"openssh-tests","binary_version":"1:9.6p1-3ubuntu1"},{"binary_name":"ssh","binary_version":"1:9.6p1-3ubuntu1"},{"binary_name":"ssh-askpass-gnome","binary_version":"1:9.6p1-3ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-51384.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-14","1:7.5p1-15","1:7.5p1-15build1","1:7.5p1-16"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client-ssh1","binary_version":"1:7.5p1-16"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-51384.json"}}],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-51384"},{"type":"REPORT","url":"https://www.openwall.com/lists/oss-security/2023/12/18/2"},{"type":"REPORT","url":"https://www.openssh.com/txt/release-9.6"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6565-1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-51384"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}