As cited
Copy frozen at (site build).
vulnerabilities
Locking your ssh-agent exposed local-only keys until OpenSSH 10.5
OpenSSH 10.4 contained a vulnerability where locking the ssh-agent disabled the check that distinguishes between local requests and forwarded connections from remote servers. This allowed an attacker with access to a forwarded agent socket to request signatures with keys that should have been restricted to local use only. The issue was patched in OpenSSH 10.5, released today.
Why it matters: System administrators and developers using ssh-agent with key forwarding should upgrade to OpenSSH 10.5 to prevent local key exposure through locked agent connections.
- Source published
- First seen by Cybersecurity Tracker