CVE-2023-5616: Canonical Ubuntu Linux
Medium severity, CVSS 4.9. EPSS: 0.2% chance of exploitation in the next 30 days.
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
Affected products
- Canonical Ubuntu Linux: version 20.04 only; version 22.04 only; version 23.04 only; version 23.10 only
- Gnome Control Center: from 1.3, before 1.3.36.5-0ubuntu4.1 (fixed in 1.3.36.5-0ubuntu4.1); from 1.41, before 1.41.7-0ubuntu0.22.04.8 (fixed in 1.41.7-0ubuntu0.22.04.8); from 1.44, before 1.44.0-1ubuntu6.1 (fixed in 1.44.0-1ubuntu6.1); from 1.45, before 1.45.0-1ubuntu3.1 (fixed in 1.45.0-1ubuntu3.1)
Published 2025-04-15. Last modified 2026-06-17.