/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2023-51767

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-51767

CGA ID

CGA-48mc-52qc-4c82

Severity

7.0

High

CVSS V3

Description

OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs