Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:4428 - Security Advisory
Issued:
2023-08-02
Updated:
2023-08-02

RHSA-2023:4428 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: openssh security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for openssh is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.

Security Fix(es):

  • openssh: Remote code execution in ssh-agent PKCS#11 support (CVE-2023-38408)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing this update, the OpenSSH server daemon (sshd) will be restarted automatically.

Affected Products

  • Red Hat Enterprise Linux Server 6 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 6 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 6 i386
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 6 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 i386
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) 6 s390x

Fixes

  • BZ - 2224173 - CVE-2023-38408 openssh: Remote code execution in ssh-agent PKCS#11 support

CVEs

  • CVE-2023-38408

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server 6

SRPM
openssh-5.3p1-125.el6_10.src.rpm SHA-256: d4018f46f50c49e9ee2538728ecef9a2d6469dfb8558ca1ddc85a9af39b2d8d8
x86_64
openssh-5.3p1-125.el6_10.x86_64.rpm SHA-256: 54cdf7b5f4ba1fd7632d96752db06edf8cf0eb80dca7706f7c5d6d579ec1c134
openssh-askpass-5.3p1-125.el6_10.x86_64.rpm SHA-256: fa6ddf2a20e0f85f7ba86b4694dcea6708258b929124744bd80a8e9681aa1c9e
openssh-clients-5.3p1-125.el6_10.x86_64.rpm SHA-256: 6ab8cabd57d6c8d95cb4d08f25ab25e57a0baf5347727c452a06e943b12ea752
openssh-debuginfo-5.3p1-125.el6_10.x86_64.rpm SHA-256: ac3208e4786a4211a064ddabde1974032d2fc25ea1aef569fc51436b638457e8
openssh-ldap-5.3p1-125.el6_10.x86_64.rpm SHA-256: a242b0bed067f25d8a3859ddf2914ba1ebc4e941ed449978b9618f4cc21c9ee0
openssh-server-5.3p1-125.el6_10.x86_64.rpm SHA-256: 7debdc595471ae269383e0787299860233dc6fdb396a99656ec22f21ae9619de
pam_ssh_agent_auth-0.9.3-125.el6_10.i686.rpm SHA-256: ba236ebaf3eaa4d6a97ef45ea25db480c9b600314777dbe33db2ced52cb57a5b
pam_ssh_agent_auth-0.9.3-125.el6_10.x86_64.rpm SHA-256: ba93f24eb3e837aa6a1c6c2bc4f83bad3f8312fdd16885041a1db3e5090879c5

Red Hat Enterprise Linux Server - Extended Life Cycle Support 6

SRPM
openssh-5.3p1-125.el6_10.src.rpm SHA-256: d4018f46f50c49e9ee2538728ecef9a2d6469dfb8558ca1ddc85a9af39b2d8d8
x86_64
openssh-5.3p1-125.el6_10.x86_64.rpm SHA-256: 54cdf7b5f4ba1fd7632d96752db06edf8cf0eb80dca7706f7c5d6d579ec1c134
openssh-askpass-5.3p1-125.el6_10.x86_64.rpm SHA-256: fa6ddf2a20e0f85f7ba86b4694dcea6708258b929124744bd80a8e9681aa1c9e
openssh-clients-5.3p1-125.el6_10.x86_64.rpm SHA-256: 6ab8cabd57d6c8d95cb4d08f25ab25e57a0baf5347727c452a06e943b12ea752
openssh-debuginfo-5.3p1-125.el6_10.i686.rpm SHA-256: 6c9610639ed8b3bfad4387cd0a499fe0798c24b9ab57aa1861a2ce21973b92ad
openssh-debuginfo-5.3p1-125.el6_10.x86_64.rpm SHA-256: ac3208e4786a4211a064ddabde1974032d2fc25ea1aef569fc51436b638457e8
openssh-debuginfo-5.3p1-125.el6_10.x86_64.rpm SHA-256: ac3208e4786a4211a064ddabde1974032d2fc25ea1aef569fc51436b638457e8
openssh-ldap-5.3p1-125.el6_10.x86_64.rpm SHA-256: a242b0bed067f25d8a3859ddf2914ba1ebc4e941ed449978b9618f4cc21c9ee0
openssh-server-5.3p1-125.el6_10.x86_64.rpm SHA-256: 7debdc595471ae269383e0787299860233dc6fdb396a99656ec22f21ae9619de
pam_ssh_agent_auth-0.9.3-125.el6_10.i686.rpm SHA-256: ba236ebaf3eaa4d6a97ef45ea25db480c9b600314777dbe33db2ced52cb57a5b
pam_ssh_agent_auth-0.9.3-125.el6_10.x86_64.rpm SHA-256: ba93f24eb3e837aa6a1c6c2bc4f83bad3f8312fdd16885041a1db3e5090879c5
i386
openssh-5.3p1-125.el6_10.i686.rpm SHA-256: 73202f230ab630d1e512acf4ea04d148671e0d920d0e864f91273ff43ef885ca
openssh-askpass-5.3p1-125.el6_10.i686.rpm SHA-256: e775219078ba03880199c13e587ab29296d4d34632a4d247d8fa36c0820d0904
openssh-clients-5.3p1-125.el6_10.i686.rpm SHA-256: 8f79fde2007e29cfe1cbc5bfa7bc131fab56c561208f299130f25cabb580ba41
openssh-debuginfo-5.3p1-125.el6_10.i686.rpm SHA-256: 6c9610639ed8b3bfad4387cd0a499fe0798c24b9ab57aa1861a2ce21973b92ad
openssh-debuginfo-5.3p1-125.el6_10.i686.rpm SHA-256: 6c9610639ed8b3bfad4387cd0a499fe0798c24b9ab57aa1861a2ce21973b92ad
openssh-ldap-5.3p1-125.el6_10.i686.rpm SHA-256: b003a8a0a3fc9c9ce13781c9d5daa627c1cce8a11faac08e654521386e10e1d6
openssh-server-5.3p1-125.el6_10.i686.rpm SHA-256: 7f0dee945949dfe216c931acf91d5bd911a97c785b0fc05be63c32e246567d0b
pam_ssh_agent_auth-0.9.3-125.el6_10.i686.rpm SHA-256: ba236ebaf3eaa4d6a97ef45ea25db480c9b600314777dbe33db2ced52cb57a5b

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 6

SRPM
openssh-5.3p1-125.el6_10.src.rpm SHA-256: d4018f46f50c49e9ee2538728ecef9a2d6469dfb8558ca1ddc85a9af39b2d8d8
s390x
openssh-5.3p1-125.el6_10.s390x.rpm SHA-256: 43a8578e293260d349b975d053e5a948bebc31df89472d9fbc4fdbeef6b58b3b
openssh-askpass-5.3p1-125.el6_10.s390x.rpm SHA-256: d67d47fc52143c53b3ddedc9042621e13265bb0b4e2e312e23568729f6127315
openssh-clients-5.3p1-125.el6_10.s390x.rpm SHA-256: 673b536df5ac9c9c47c664a6546cab11da0e6fd14665110d1ebbced3d60c580e
openssh-debuginfo-5.3p1-125.el6_10.s390.rpm SHA-256: 79b6bd9433670d7ee9c0b0bba291b326f6c0dd5991982dbbfefb41a8db3dc0c8
openssh-debuginfo-5.3p1-125.el6_10.s390x.rpm SHA-256: f4954c9834f010f5aab04251b53af20be2c566c61491f764fec08607111c5fc2
openssh-debuginfo-5.3p1-125.el6_10.s390x.rpm SHA-256: f4954c9834f010f5aab04251b53af20be2c566c61491f764fec08607111c5fc2
openssh-ldap-5.3p1-125.el6_10.s390x.rpm SHA-256: 00e5c3016fe40e50e89486305ed21ba38369682b41c8b98bba8e4ab95bb63aa9
openssh-server-5.3p1-125.el6_10.s390x.rpm SHA-256: 9acb7e79fc81c24ead74015d83c298208a3bbdd3f77dd5e9173f10e86758718c
pam_ssh_agent_auth-0.9.3-125.el6_10.s390.rpm SHA-256: efb0cddbaf4d02d8df3cfa9329057d528b64e086cbab3910c7a885dc3f1eeb56
pam_ssh_agent_auth-0.9.3-125.el6_10.s390x.rpm SHA-256: 9477990cb668524036b5d8903a0b6419aed0a28ac5320fd5b51f78c9706ea47f

Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6

SRPM
openssh-5.3p1-125.el6_10.src.rpm SHA-256: d4018f46f50c49e9ee2538728ecef9a2d6469dfb8558ca1ddc85a9af39b2d8d8
x86_64
openssh-5.3p1-125.el6_10.x86_64.rpm SHA-256: 54cdf7b5f4ba1fd7632d96752db06edf8cf0eb80dca7706f7c5d6d579ec1c134
openssh-askpass-5.3p1-125.el6_10.x86_64.rpm SHA-256: fa6ddf2a20e0f85f7ba86b4694dcea6708258b929124744bd80a8e9681aa1c9e
openssh-clients-5.3p1-125.el6_10.x86_64.rpm SHA-256: 6ab8cabd57d6c8d95cb4d08f25ab25e57a0baf5347727c452a06e943b12ea752
openssh-debuginfo-5.3p1-125.el6_10.i686.rpm SHA-256: 6c9610639ed8b3bfad4387cd0a499fe0798c24b9ab57aa1861a2ce21973b92ad
openssh-debuginfo-5.3p1-125.el6_10.x86_64.rpm SHA-256: ac3208e4786a4211a064ddabde1974032d2fc25ea1aef569fc51436b638457e8
openssh-debuginfo-5.3p1-125.el6_10.x86_64.rpm SHA-256: ac3208e4786a4211a064ddabde1974032d2fc25ea1aef569fc51436b638457e8
openssh-ldap-5.3p1-125.el6_10.x86_64.rpm SHA-256: a242b0bed067f25d8a3859ddf2914ba1ebc4e941ed449978b9618f4cc21c9ee0
openssh-server-5.3p1-125.el6_10.x86_64.rpm SHA-256: 7debdc595471ae269383e0787299860233dc6fdb396a99656ec22f21ae9619de
pam_ssh_agent_auth-0.9.3-125.el6_10.i686.rpm SHA-256: ba236ebaf3eaa4d6a97ef45ea25db480c9b600314777dbe33db2ced52cb57a5b
pam_ssh_agent_auth-0.9.3-125.el6_10.x86_64.rpm SHA-256: ba93f24eb3e837aa6a1c6c2bc4f83bad3f8312fdd16885041a1db3e5090879c5
i386
openssh-5.3p1-125.el6_10.i686.rpm SHA-256: 73202f230ab630d1e512acf4ea04d148671e0d920d0e864f91273ff43ef885ca
openssh-askpass-5.3p1-125.el6_10.i686.rpm SHA-256: e775219078ba03880199c13e587ab29296d4d34632a4d247d8fa36c0820d0904
openssh-clients-5.3p1-125.el6_10.i686.rpm SHA-256: 8f79fde2007e29cfe1cbc5bfa7bc131fab56c561208f299130f25cabb580ba41
openssh-debuginfo-5.3p1-125.el6_10.i686.rpm SHA-256: 6c9610639ed8b3bfad4387cd0a499fe0798c24b9ab57aa1861a2ce21973b92ad
openssh-debuginfo-5.3p1-125.el6_10.i686.rpm SHA-256: 6c9610639ed8b3bfad4387cd0a499fe0798c24b9ab57aa1861a2ce21973b92ad
openssh-ldap-5.3p1-125.el6_10.i686.rpm SHA-256: b003a8a0a3fc9c9ce13781c9d5daa627c1cce8a11faac08e654521386e10e1d6
openssh-server-5.3p1-125.el6_10.i686.rpm SHA-256: 7f0dee945949dfe216c931acf91d5bd911a97c785b0fc05be63c32e246567d0b
pam_ssh_agent_auth-0.9.3-125.el6_10.i686.rpm SHA-256: ba236ebaf3eaa4d6a97ef45ea25db480c9b600314777dbe33db2ced52cb57a5b

Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) 6

SRPM
openssh-5.3p1-125.el6_10.src.rpm SHA-256: d4018f46f50c49e9ee2538728ecef9a2d6469dfb8558ca1ddc85a9af39b2d8d8
s390x
openssh-5.3p1-125.el6_10.s390x.rpm SHA-256: 43a8578e293260d349b975d053e5a948bebc31df89472d9fbc4fdbeef6b58b3b
openssh-askpass-5.3p1-125.el6_10.s390x.rpm SHA-256: d67d47fc52143c53b3ddedc9042621e13265bb0b4e2e312e23568729f6127315
openssh-clients-5.3p1-125.el6_10.s390x.rpm SHA-256: 673b536df5ac9c9c47c664a6546cab11da0e6fd14665110d1ebbced3d60c580e
openssh-debuginfo-5.3p1-125.el6_10.s390.rpm SHA-256: 79b6bd9433670d7ee9c0b0bba291b326f6c0dd5991982dbbfefb41a8db3dc0c8
openssh-debuginfo-5.3p1-125.el6_10.s390x.rpm SHA-256: f4954c9834f010f5aab04251b53af20be2c566c61491f764fec08607111c5fc2
openssh-debuginfo-5.3p1-125.el6_10.s390x.rpm SHA-256: f4954c9834f010f5aab04251b53af20be2c566c61491f764fec08607111c5fc2
openssh-ldap-5.3p1-125.el6_10.s390x.rpm SHA-256: 00e5c3016fe40e50e89486305ed21ba38369682b41c8b98bba8e4ab95bb63aa9
openssh-server-5.3p1-125.el6_10.s390x.rpm SHA-256: 9acb7e79fc81c24ead74015d83c298208a3bbdd3f77dd5e9173f10e86758718c
pam_ssh_agent_auth-0.9.3-125.el6_10.s390.rpm SHA-256: efb0cddbaf4d02d8df3cfa9329057d528b64e086cbab3910c7a885dc3f1eeb56
pam_ssh_agent_auth-0.9.3-125.el6_10.s390x.rpm SHA-256: 9477990cb668524036b5d8903a0b6419aed0a28ac5320fd5b51f78c9706ea47f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility