CVE-2023-38408: Fedoraproject Fedora

Critical severity, CVSS 9.8. EPSS: 79.7% chance of exploitation in the next 30 days.

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

Affected products

  • Fedoraproject Fedora: version 37 only; version 38 only
  • OpenBSD OpenSSH: before 9.3 (fixed in 9.3); version 9.3 only

Published 2023-07-20. Last modified 2026-06-17.