CYBERSECURITYTRACKER
TRACKING7,735 stories in this site build1,671 vulnerability news stories in this site build
Permanent story citation

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4205

As cited

Copy frozen at (site build).

vulnerabilities

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5

OpenSSH 10.4 contained a vulnerability where locking the ssh-agent disabled the check that distinguishes between local requests and forwarded connections from remote servers. This allowed an attacker with access to a forwarded agent socket to request signatures with keys that should have been restricted to local use only. The issue was patched in OpenSSH 10.5, released today.

Why it matters: System administrators and developers using ssh-agent with key forwarding should upgrade to OpenSSH 10.5 to prevent local key exposure through locked agent connections.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary