openssh: an integer overflow in the private key parsing code for the XMSS key type
Published Oct 9, 2019
7.8
HIGHCVSS 3.1
EPSS 2.17%
Description
OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.
Affected products
No data.
Configuration 1
Configuration 2
- n/a
- n/a
Configuration 3
- < 3.2.7
Running on/with
- n/a
Configuration 4
- < 3.2.7
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 5
openssh
Not affected
Red Hat Enterprise Linux 6
openssh
Not affected
Red Hat Enterprise Linux 7
openssh
Not affected
Red Hat Enterprise Linux 8
openssh
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | openssh | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssh | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssh | Not affected | n/a |
| Red Hat Enterprise Linux 8 | openssh | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The versions of OpenSSH package shipped with Red Hat products, do not enable support for XMSS and therefore are not affected by this flaw.
Red Hat mitigation
This flaw is triggered when parsing XMSS private keys. XMSS is a PQC (Post-quantum cryptography) algorithm and its use is currently experimental. Other key types or any other OpenSSH functionality are not affected by this flaw. A possible mitigation for this flaw is to NOT use XMSS keys for SSH.
References (15)
- https://access.redhat.com/security/cve/CVE-2019-16905 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1767966 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1153537 Issue TrackingThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf Third Party Advisory
- https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshkey-xmss.c Release NotesVendor Advisory
- https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshkey-xmss.c.diff?r1=1.5&r2=1.6&f=h Patch
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-7402 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-16905
- https://security.gentoo.org/glsa/201911-01 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20191024-0003/ Third Party Advisory
- https://ssd-disclosure.com/archives/4033/ssd-advisory-openssh-pre-auth-xmss-integer-overflow ExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-16905
- https://www.openssh.com/releasenotes.html Release Notes
- https://www.openssh.com/txt/release-8.1
- https://www.openwall.com/lists/oss-security/2019/10/09/1 Mailing ListThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data