[ubuntu/focal-security] openssh 1:8.2p1-4ubuntu0.8 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Mon Jul 24 16:31:11 UTC 2023

openssh (1:8.2p1-4ubuntu0.8) focal-security; urgency=medium

  * SECURITY UPDATE: remote code execution relating to PKCS#11 providers
    - debian/patches/CVE-2023-38408-1.patch: terminate process if requested
      to load a PKCS#11 provider that isn't a PKCS#11 provider in
    - debian/patches/CVE-2023-38408-3.patch: ensure FIDO/PKCS11 libraries
      contain expected symbols in misc.c, misc.h, ssh-pkcs11.c, ssh-sk.c.
    - CVE-2023-38408

openssh (1:8.2p1-4ubuntu0.7) focal; urgency=medium

  * d/p/lp2012298-upstream-fix-match-in-d-config.patch: Allow ssh_config.d/
    configuration files to correctly update the PasswordAuthentication setting
    (LP: #2012298)

openssh (1:8.2p1-4ubuntu0.6) focal; urgency=medium

  * d/p/fix-outdated-info-ssh-conf.patch: Fix outdated information
    (LP: #1871465)

openssh (1:8.2p1-4ubuntu0.5) focal; urgency=medium

  * d/p/fix-connect-timeout-overflow.patch: prevent ConnectTimeout overflow.
    (LP: #1903516)

  [ Sergio Durigan Junior ]
  * d/p/lp1966591-upstream-preserve-group-world-read-permission-on-kno.patch:
    Preserve group/world read permissions on known_hosts. (LP: #1966591)

openssh (1:8.2p1-4ubuntu0.4) focal; urgency=medium

  * d/p/match-host-certs-w-public-keys.patch: Add patch
    to match host certificates agianst host public keys.
    (LP: #1952421)

openssh (1:8.2p1-4ubuntu0.3) focal; urgency=medium

  * d/systemd/ssh at .service: preserve the systemd managed runtime directory to
    ensure parallel processes will not disrupt one another when halting
    (LP: #1905285)

Date: 2023-07-20 14:03:08.559512+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
-------------- next part --------------
Sorry, changesfile not available.

More information about the Focal-changes mailing list