Release of OpenSSH 8.6 addressing vulnerabilities

The release of OpenSSH 8.6 has been published, an open implementation of the client and server for working with SSH 2.0 and SFTP protocols. The new version fixes a vulnerability in the implementation of the LogVerbose directive that appeared in the previous release, allowing for an increase in the level of debugging information logged, including the ability to filter by patterns, functions, and files associated with code executed with dropped privileges in the sshd process, isolated in a sandbox environment.

An attacker who gains control over an unprivileged process through some yet unknown vulnerability can exploit the LogVerbose issue to bypass the sandbox isolation and attack a process running with elevated privileges. The practical application of the LogVerbose vulnerability is assessed as unlikely, since the LogVerbose setting is disabled by default and is typically used only during debugging. Additionally, the attacker would need to find a new vulnerability in the unprivileged process.

Changes in OpenSSH 8.6 unrelated to the vulnerability:

  • A new protocol extension 'limits@openssh.com' has been implemented in sftp and sftp-server, allowing the SFTP client to retrieve information about the established limits, including limits on maximum packet size and read/write operations. In sftp, the new extension is utilized to select the optimal block size during data transfer. server A new configuration option ModuliFile has been added to sshd_config for sshd, allowing the specification of the path to the 'moduli' file containing groups for DH-GEX.
  • An environment variable TEST_SSH_ELAPSED_TIMES has been added to the unit tests to enable output of the time elapsed since the start of each test.
  • The password prompt interface for GNOME has been split into two variants, one for GNOME2 and another for GNOME3 (contrib/gnome-ssk-askpass3.c). The version for GNOME3 improves compatibility with Wayland by using the gdk_seat_grab() call to manage keyboard and mouse grabbing.
  • A soft-disallow for the fstatat64 system call has been added to the seccomp-bpf based sandbox used in Linux.
  • Jonathan Carter has been re-elected as the leader of the Debian project.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster