CVE-2023-48795

Terrapin: an attacker on the wire can delete the first messages of a session

A flaw in the SSH transport protocol itself rather than in one implementation. Someone positioned between client and server can silently remove messages sent at the start of a connection, before either end would notice.

OpenSSHNot in CISA’s Known Exploited catalogueEPSS 93.3% chance of an attempt in 30 daysCVSS 5.9CWE-354CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

A fixed package version is available on 5 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

SSH numbers its messages, but the sequence numbers are not covered by the handshake that agrees on encryption. That lets a machine in the middle drop specific early packets and have both ends carry on as though nothing happened. The practical effect is downgrading protections negotiated in those first messages.

What an attacker gets: The ability to strip a security feature agreed during the handshake, for an attacker who is already able to intercept and modify the connection.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • It requires an active position on the network path. This is not something an internet scanner can do to you.
  • It only applies when certain algorithms are in use, notably ChaCha20-Poly1305 and the CBC ciphers with Encrypt-then-MAC. A server restricted to AES-GCM was never affected.
  • Both ends need fixing. Patching the server does nothing for a session where the client is still vulnerable, and vice versa.

Check your own server

Read-only, changes nothing
ssh -Q cipher | head -20 && echo '---' && grep -iE '^(Ciphers|MACs)' /etc/ssh/sshd_config

Shows which ciphers the build offers and which the configuration allows. Fixed versions negotiate a strict key exchange that closes the hole; older ones need the algorithms restricted instead.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSopensshFixed1:8.9p1-3ubuntu0.5
Ubuntu 24.04 LTSopensshFixed1:9.6p1-3ubuntu1
Debian 12 (bookworm)opensshFixed1:9.2p1-2+deb12u2
Debian 13 (trixie)opensshFixed1:9.6p1-1
Rocky Linux 9opensshNo advisory names itno advisory for this release names it
AlmaLinux 9opensshFixed8.7p1-34.el9_3.3

Install the fix with apt update && apt install --only-upgrade openssh-server openssh-client on Debian and Ubuntu, or dnf update openssh-server openssh-clients on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in [email protected] and (if CBC is used) the [email protected] MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.

Recorded from nvd. Its weakness class is CWE-354, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2023-48795 included. It changes nothing.