# Openssh 8.0p1 does not contain the latest cve? Running version rocky 8.10

**URL:** <https://forums.rockylinux.org/t/openssh-8-0p1-does-not-contain-the-latest-cve-running-version-rocky-8-10/17283>\
**Category:** Rocky Linux Help & Support\
**Tags:** rocky-linux-8\
**Created:** [January 23, 2025, 3:19pm UTC](https://forums.rockylinux.org/t/openssh-8-0p1-does-not-contain-the-latest-cve-running-version-rocky-8-10/17283 "2025-01-23T15:19:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ucfjerry](https://avatars.discourse-cdn.com/v4/letter/u/e9bcb4/32.png) [@ucfjerry](https://forums.rockylinux.org/u/ucfjerry)\
**Post date:** [January 23, 2025, 3:19pm UTC](https://forums.rockylinux.org/t/openssh-8-0p1-does-not-contain-the-latest-cve-running-version-rocky-8-10/17283/1 "2025-01-23T15:19:04Z")

</div>

The latest CVE for openssh are not installed. What could be the issue? RLSA-2024:0606 was released in February but not listed in my command rpm -q openssh --changelog | grep CVE

---

<div class="post-metadata">

**Author:** ![sspencerwire](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@sspencerwire](https://forums.rockylinux.org/u/sspencerwire)\
**Post date:** [January 23, 2025, 3:30pm UTC](https://forums.rockylinux.org/t/openssh-8-0p1-does-not-contain-the-latest-cve-running-version-rocky-8-10/17283/2 "2025-01-23T15:30:09Z")

</div>

Are you using aarch64 packages? It appears that this only affects those.  
[https://errata.rockylinux.org/RLSA-2024:0606](https://errata.rockylinux.org/RLSA-2024:0606)

---

<div class="post-metadata">

**Author:** ![ucfjerry](https://avatars.discourse-cdn.com/v4/letter/u/e9bcb4/32.png) [@ucfjerry](https://forums.rockylinux.org/u/ucfjerry)\
**Post date:** [January 23, 2025, 4:35pm UTC](https://forums.rockylinux.org/t/openssh-8-0p1-does-not-contain-the-latest-cve-running-version-rocky-8-10/17283/3 "2025-01-23T16:35:27Z")

</div>

good information sspencerwire. thank you

our security audit is flagging openssh for  
CVE-2023-51385  
CVE-2023-38408  
CVE-2023-48795  
when i run the rpm -q openssh --changelog | grep CVE command i see CVE-2023038408 fixed but nothing newer than 2023.

- Providing a kill switch for scp to deal with CVE-2020-15778  
Related: CVE-2023-38408  
Resolves: CVE-2023-38408
- CVE-2021-41617 upstream fix (#2008885)
- CVE-2020-14145 openssh: Observable Discrepancy leading to an information
- New upstream release fixing CVE 2018-15473
- CVE-2016-6210: User enumeration via covert timing channel (#1357443)
- CVE-2015-8325: ignore PAM environment vars when UseLogin=yes (#1328013)

is the CVE flagged not applicable to my os?

i think 8.10 is still supported but why is it not showing the latest cve fixes? server was just updated. Perhaps the older openssh the new cve does not pertain to ? or am i not getting openssh patches?

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [January 23, 2025, 5:00pm UTC](https://forums.rockylinux.org/t/openssh-8-0p1-does-not-contain-the-latest-cve-running-version-rocky-8-10/17283/4 "2025-01-23T17:00:06Z")

</div>

> [@ucfjerry](#):
>
> RLSA-2024:0606 was released in February

This package has long since been superseded by `openssh-8.0p1-25.el8_10`, which contains the fixes for the CVE’s your scanner is saying you’re affected by.

> [@ucfjerry](#):
>
> CVE-2023-51385  
> CVE-2023-48795

These CVE’s were fixed in 8.0p1-22 and 8.0p1-23, addressing terrapin and metasymbol injection.

> [@ucfjerry](#):
>
> CVE-2023-38408

This was very clearly addressed in 8.0p1-18, as noted by the change log.

* * *

As noted earlier, `openssh-8.0p1-25.el8_10` has long since superseded the versions of packages those CVE’s were originally fixed in, and thus the fixes are there. Please work with your auditors or the creators of your software/scanner to fix these false positives.

---

<div class="post-metadata">

**Author:** ![ucfjerry](https://avatars.discourse-cdn.com/v4/letter/u/e9bcb4/32.png) [@ucfjerry](https://forums.rockylinux.org/u/ucfjerry)\
**Post date:** [January 23, 2025, 5:38pm UTC](https://forums.rockylinux.org/t/openssh-8-0p1-does-not-contain-the-latest-cve-running-version-rocky-8-10/17283/5 "2025-01-23T17:38:51Z")

</div>

Hi nazunalika. Thank you for the feedback.  
Is there a url for the openssh version im running change log that i can review with my infosec team?

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [January 23, 2025, 5:50pm UTC](https://forums.rockylinux.org/t/openssh-8-0p1-does-not-contain-the-latest-cve-running-version-rocky-8-10/17283/6 "2025-01-23T17:50:17Z")

</div>

You can find all Rocky Linux 8 openssh packages here.

[https://kojidev.rockylinux.org/koji/packageinfo?packageID=346](https://kojidev.rockylinux.org/koji/packageinfo?packageID=346)

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [January 24, 2025, 8:48am UTC](https://forums.rockylinux.org/t/openssh-8-0p1-does-not-contain-the-latest-cve-running-version-rocky-8-10/17283/7 "2025-01-24T08:48:42Z")

</div>

> [@ucfjerry](#):
>
> the openssh version im running change log

The RPM packages do include change logs, so for installed package one can read the log with:

```bash
rpm -q --changelog openssh

```

One can read logs for non-installed packages too:

```bash
dnf changelog openssh

```

(and could narrow that down to specific, non-latest, version – as long as repo has it or it is installed)

Some packages have very long changelogs, so `less` or `grep` come handy.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/1X/91b7219eec10e30013422e4df76c1d898711a5d5.svg) [@system](https://forums.rockylinux.org/u/system)\
**Post date:** [March 25, 2025, 8:49am UTC](https://forums.rockylinux.org/t/openssh-8-0p1-does-not-contain-the-latest-cve-running-version-rocky-8-10/17283/8 "2025-03-25T08:49:36Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
