CVE-2023-51384: Debian Linux
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.
Affected products
- Debian Debian Linux: version 11.0 only; version 12.0 only
- OpenBSD OpenSSH: from 8.9, before 9.6 (fixed in 9.6)
Published 2023-12-18. Last modified 2026-07-14.