{"dataType":"CVE_RECORD","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2023-51767","assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","dateUpdated":"2025-11-18T22:03:38.917Z","dateReserved":"2023-12-24T00:00:00.000Z","datePublished":"2023-12-24T00:00:00.000Z"},"containers":{"cna":{"providerMetadata":{"orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre","dateUpdated":"2025-09-22T16:42:44.854Z"},"descriptions":[{"lang":"en","value":"OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. NOTE: this is disputed by the Supplier, who states \"we do not consider it to be the application's responsibility to defend against platform architectural weaknesses.\""}],"affected":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}],"references":[{"url":"https://arxiv.org/abs/2309.02545"},{"url":"https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878"},{"url":"https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2255850"},{"url":"https://access.redhat.com/security/cve/CVE-2023-51767"},{"url":"https://ubuntu.com/security/CVE-2023-51767"},{"url":"https://security.netapp.com/advisory/ntap-20240125-0006/"},{"url":"https://www.openwall.com/lists/oss-security/2025/09/22/1"}],"problemTypes":[{"descriptions":[{"type":"text","lang":"en","description":"n/a"}]}],"tags":["disputed"]},"adp":[{"title":"CVE Program Container","references":[{"url":"https://arxiv.org/abs/2309.02545","tags":["x_transferred"]},{"url":"https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878","tags":["x_transferred"]},{"url":"https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77","tags":["x_transferred"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2255850","tags":["x_transferred"]},{"url":"https://access.redhat.com/security/cve/CVE-2023-51767","tags":["x_transferred"]},{"url":"https://ubuntu.com/security/CVE-2023-51767","tags":["x_transferred"]},{"url":"https://security.netapp.com/advisory/ntap-20240125-0006/","tags":["x_transferred"]},{"url":"http://www.openwall.com/lists/oss-security/2025/10/01/1"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/22/1"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/24/4"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/22/2"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/23/4"},{"url":"http://www.openwall.com/lists/oss-security/2025/10/01/2"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/26/2"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/26/4"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/27/1"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/27/2"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/27/3"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/27/5"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/27/6"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/27/7"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/29/4"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/29/5"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/23/1"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/29/6"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/23/3"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/23/5"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/24/7"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/25/2"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/25/6"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/27/4"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/28/7"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/29/1"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-18T22:03:38.917Z"}}]},"dataVersion":"5.2"}