]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/commit
Implement "strict key exchange" in ssh and sshd.
authorGordon Tetlow <gordon@FreeBSD.org>
Mon, 18 Dec 2023 16:22:22 +0000 (08:22 -0800)
committerGordon Tetlow <gordon@FreeBSD.org>
Mon, 18 Dec 2023 16:22:22 +0000 (08:22 -0800)
commit92f58c69a14c0afe910145f177c0e8aeaf9c7da4
treee471b4c3fad0d66f9dc8a614d36a00faed1733b6
parent18e2c4175f78f1aaa648dd7fb7530220aed23671
Implement "strict key exchange" in ssh and sshd.

This adds a protocol extension to improve the integrity of the SSH
transport protocol, particular in and around the initial key exchange
(KEX) phase.

Full details of the extension are in the PROTOCOL file.

OpenBSD-Commit-ID: 2a66ac962f0a630d7945fee54004ed9e9c439f14

Approved by: so (implicit)
Obtained from: https://anongit.mindrot.org/openssh.git/patch/?id=1edb00c58f8a6875fad6a497aa2bacf37f9e6cd5
Security: CVE-2023-48795
crypto/openssh/PROTOCOL
crypto/openssh/kex.c
crypto/openssh/kex.h
crypto/openssh/packet.c
crypto/openssh/packet.h
crypto/openssh/sshconnect2.c