>Probably not.
(I will preface this by saying I'm likely missing something obvious.)
I am an admin, and it's not clear _how_ I might fix this at the server end.
Edit: thanks for the replies, I'll sit tight for now.
>Probably not.
(I will preface this by saying I'm likely missing something obvious.)
I am an admin, and it's not clear _how_ I might fix this at the server end.
Edit: thanks for the replies, I'll sit tight for now.
You're just hearing about this early as it's the first hours of public disclosure. There are 3 CVE's assigned. You'll track those with your vendors or upstream and patch as fixes become available, which they already should be for at least some implementations that had earlier disclosure. The main issue is CVE-2023-48795. It does not appear there is any immediate need to implement compensating controls or workarounds at this time, but that assessment really depends on your own environment, security policy, and risk tolerance.
For packages, openssh and openssh-portable 9.6 include the fix, but every vendor will need to backport if they maintain their own pile of patches against a particular version of -portable.