Bug 2234394

Summary: CVE-2023-38408 in CentOS Stream 8 still not fixed
Product: Red Hat Enterprise Linux 8 Reporter: Armin Kunaschik <armin.kunaschik>
Component: opensshAssignee: Dmitry Belyavskiy <dbelyavs>
Status: CLOSED CURRENTRELEASE QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: high Docs Contact:
Priority: high    
Version: 8.0CC: jjelen
Target Milestone: rcKeywords: Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-08-28 08:00:12 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Armin Kunaschik 2023-08-24 09:53:52 UTC
Description of problem:
The fix for CVE-2023-38408 is still missing in Centos 8 Stream. RHEL 8 received it already weeks ago. According to the RHEL 8 release, the package version where it's fixed is openssh-8.0p1-18.
According to the actual CVE rating I'm setting the severity to high.

Version-Release number of selected component (if applicable):
openssh-8.0p1-17

How reproducible:


Steps to Reproduce:
1.
2.
3.

Actual results:


Expected results:


Additional info:

Comment 1 Dmitry Belyavskiy 2023-08-24 12:15:22 UTC
Thanks for the reminder, will do.

Comment 3 Dmitry Belyavskiy 2023-08-28 08:00:12 UTC
The bug has landed in the distro, thanks for letting me know.

Comment 4 Armin Kunaschik 2023-08-28 17:25:02 UTC
Thanks for the quick fix!