Description
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5586-1 | openssh security update |
Ubuntu USN |
USN-6560-1 | OpenSSH vulnerabilities |
References
History
Tue, 12 May 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-12T10:52:17.854Z
Reserved: 2023-03-17T00:00:00.000Z
Link: CVE-2023-28531
No data.
Status : Modified
Published: 2023-03-17T04:15:14.553
Modified: 2026-05-12T11:16:12.560
Link: CVE-2023-28531
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN