HomeFreeBSD

Implement "strict key exchange" in ssh and sshd.

Description

Implement "strict key exchange" in ssh and sshd.

This adds a protocol extension to improve the integrity of the SSH
transport protocol, particular in and around the initial key exchange
(KEX) phase.

Full details of the extension are in the PROTOCOL file.

OpenBSD-Commit-ID: 2a66ac962f0a630d7945fee54004ed9e9c439f14

Approved by: so (implicit)
Obtained from: https://anongit.mindrot.org/openssh.git/patch/?id=1edb00c58f8a6875fad6a497aa2bacf37f9e6cd5
Security: CVE-2023-48795

(cherry picked from commit 92f58c69a14c0afe910145f177c0e8aeaf9c7da4)

Details

Provenance
gordonAuthored on Dec 18 2023, 4:22 PM
Parents
rGa9184e99afe8: kthread: Set *newtdp earlier in kthread_add1()
Branches
Unknown
Tags
Unknown