CVE-2023-38408General(fedoraproject / fedora)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fedoraproject fedora systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-428

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fedora
  • openssh

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • General: 2 classified signals
  • False Positive: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
fedoraopenssh

3 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-24: 1Mentions · 2026-04-16: 1Mentions · 2026-05-13: 1Patch / Workaround · 2026-04-16: 102-2404-1605-13
Signal classification2 categories
General
266.7%
False Positive
133.3%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-02-241
General1
2026-04-161
False Positive1
2026-05-131
General1
Full discourse3 posts
  • mel moreira@melmoreira35584
    General

    @DerekUrizar Urizar, I'm going to make it easy for you, with this you can access it. Target: guatemalavisible[.]net IP: 107.180.40.138 CVE: CVE-2025-67896 CVE-2024-3566 CVE-2023-38408 CVE-2022-37454 CVE-2021-41617 CVE-2020-15778 CVE-2019-16905 CVE-2017-8923 CVE-2013-2220 CVE-2008-3844

    Post summary

    The message lists a series of CVE identifiers and a target IP but provides no additional technical or operational details.

    00023677
    298 followersView on X
  • NSAuditor AI@Nsasoft
    False Positive

    Your Ubuntu server shows OpenSSH 8.2p1. Every scanner flags CVE-2023-38408. But Ubuntu backported the patch. The version string is lying. The binary is fine. Pro reads distro-level patch metadata and marks it FALSE_POSITIVE — not noise in your inbox.

    Post summary

    Scanners flag CVE-2023-38408 on an OpenSSH 8.2p1 Ubuntu server, but the patch was backported and the platform marks it as a false positive.

    1003084
    125 followersView on X
  • Himadri Singh@LittleSun4lower
    General

    I just completed CVE-2023-38408 room on TryHackMe! Learn how to move laterally abusing libraries' side effects in Ubuntu (CVE-2023-38408). https://tryhackme.com/room/cve202338408?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #learning #cve #consistency

    Post summary

    The post announces a TryHackMe learning room about CVE-2023-38408 but offers no detailed technical, exploit, patch, or active exploitation information.

    00010114
    10 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora37--
OSfedoraprojectfedora38--
Appopenbsdopenssh---
Appopenbsdopenssh9.3--
Appopenbsdopenssh9.3--

Explore more