CVE-2023-51767

Published
View on NVD ↗
CVSS v3
7
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. NOTE: this is disputed by the Supplier, who states "we do not consider it to be the application's responsibility to defend against platform architectural weaknesses."

Portable OpenSSH
GitHubGitHub
3.85K