CVE-2023-51384: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

Affected products

  • Debian Debian Linux: version 11.0 only; version 12.0 only
  • OpenBSD OpenSSH: from 8.9, before 9.6 (fixed in 9.6)

Published 2023-12-18. Last modified 2026-07-14.