Database/Kernel, userspace & hypervisor

OpenSSH (ssh-agent): Remote code execution in ssh-agent PKCS#11 support when agent forwarding reaches a hostile host
CVE-2023-38408Kernel, userspace & hypervisorcurated
Impact
Remote code execution in ssh-agent PKCS#11 support when agent forwarding reaches a hostile host
Who can reach it
Unauthenticated network (against a forwarded agent)
What to do
Package update; restart agents. Policy fix: forbid agent forwarding into tenant-reachable bastions
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.