# Upgrade openssh to 9.3p2

**URL:** <https://forums.rockylinux.org/t/upgrade-openssh-to-9-3p2/10794>\
**Category:** Rocky Linux Help & Support\
**Created:** [July 25, 2023, 10:36am UTC](https://forums.rockylinux.org/t/upgrade-openssh-to-9-3p2/10794 "2023-07-25T10:36:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kamalsai](https://avatars.discourse-cdn.com/v4/letter/k/b5e925/32.png) [@kamalsai](https://forums.rockylinux.org/u/kamalsai)\
**Post date:** [July 25, 2023, 10:36am UTC](https://forums.rockylinux.org/t/upgrade-openssh-to-9-3p2/10794/1 "2023-07-25T10:36:31Z")

</div>

**os version:** 9.2 (Blue Onyx)

i need to upgrade the openssh from OpenSSH\_8.7p1 to OpenSSH\_9.3p2 because of CVE-2023-38408  
we installed depend packages Development Tools , zlib-devel , openssl-devel , pam-devel , libselinux-devel ,  
wget -c [https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-9.3p2.tar.gz](https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-9.3p2.tar.gz)  
./configure --with-pam --with-selinux --with-privsep-path=/var/lib/sshd/ --sysconfdir=/etc/ssh  
make  
make install  
and restarted sshd  
still the version is OpenSSH\_8.7p1, OpenSSL 3.0.7 1 Nov 2022

can you please help how to upgrade openssh to 9.3p2 or can you provide openssh 9.3p2 patch for rocky 9.2

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [July 25, 2023, 11:53am UTC](https://forums.rockylinux.org/t/upgrade-openssh-to-9-3p2/10794/2 "2023-07-25T11:53:07Z")

</div>

First, one does not mess with Enterprise Linux content. A vital point of package management is that the manager tool knows what is in the system and source installs are not known in RPM-based system.

* * *

As long as Rocky is bug-for-bug compatible with RHEL it has practically same packages as RHEL.  
To get new package thus requires that Red Hat releases something new.

The current state shown in [cve-details](https://access.redhat.com/security/cve/cve-2023-38408) is that EL9 is _Affected_ – now patched package yet. That page does propose mitigations:

> ## Mitigation
> 
> Remote exploitation requires that the agent was forwarded to an attacker-controlled system.
> 
> Exploitation can also be prevented by starting ssh-agent(1) with an empty PKCS#11/FIDO allowlist (ssh-agent -P ‘’) or by configuring an allowlist that contains only specific provider libraries.  
> So disable agent forwarding or restrict ssh-agent options.

* * *

Those said, you ran `configure` with options `with-privsep-path` and `sysconfdir`. (Btw, EL9’s sshd does not seem to have/use `/var/lib/sshd/` at all.)

1. Doesn’t that leave install prefix to default (usually `/usr/local`)?
2. Systemd (re)starts `sshd.service` with unit file. Was it modified to use the new binary, (if the build did not overwrite the `/usr/sbin/sshd`)?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/1X/91b7219eec10e30013422e4df76c1d898711a5d5.svg) [@system](https://forums.rockylinux.org/u/system)\
**Post date:** [September 23, 2023, 11:53am UTC](https://forums.rockylinux.org/t/upgrade-openssh-to-9-3p2/10794/3 "2023-09-23T11:53:55Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
