I got a mail that you converted it to private and I was like "that's weird", but then I realized there's a CVE attached, which I hadn't put together. ... Severity 8.9?? Nuh-uh. Yes, it causes a crash, but the crash is to the *per-client* sshd instance. It has no effect whatsoever on the overall system. Unless someone has found an *exploit* based on this, it feels pretty low severity to me. Neither here nor there, just commenting.
Side comment: for my first attempt at a fix I tried to use the 9.0p1 SRPM plus the 9.2p1 upstream source to make a package. I now have *deep* respect for the Fedora maintainers of the openssh package. OMG *so many* patches. ;_; Wish you could upstream them, but amazing that you deal with all that!
FEDORA-2023-123647648e has been submitted as an update to Fedora 38. https://bodhi.fedoraproject.org/updates/FEDORA-2023-123647648e
FEDORA-2023-1176c8b10c has been submitted as an update to Fedora 37. https://bodhi.fedoraproject.org/updates/FEDORA-2023-1176c8b10c
Fix pushed to f37+
Many thanks for drawing my attention!
FEDORA-2023-123647648e has been pushed to the Fedora 38 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2023-123647648e` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2023-123647648e See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2023-1176c8b10c has been pushed to the Fedora 37 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2023-1176c8b10c` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2023-1176c8b10c See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
Perhaps you could un-confidential the original report now? I rather liked it and would like to be able to share it.
Oh, also, the fix totally appears to work, thank you!
FEDORA-2023-1176c8b10c has been pushed to the Fedora 37 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2023-123647648e has been pushed to the Fedora 38 stable repository. If problem still persists, please make note of it in this bug report.