
oss-sec mailing list archives
Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH
From: Peter Gutmann <pgut001 () cs auckland ac nz>
Date: Sat, 27 Sep 2025 08:43:22 +0000
Demi Marie Obenour writes:
Is there something about Rowhammer specifically that makes it an unattractive attack, even for nation-state attackers against well-protected targets?
Not Rowhammer specifically, there are a near-infinite number of gee-whiz conference-paper-worthy attacks that fall into the same category. Attackers know what works and that's what they go for. To see what works, look at any survey of attacks, for example the OWASP Top Ten. Rowhammer is at position 26,672 in that list, right next to Spectre and and Meltdown and Zenbleed and using a reflection in someone's eyeball in a selfie that shows a reflection on a window that has a reflection on a glass-encased wall image that has a reflection of a monitor that displays a password. There's no point worrying about Mission-Impossible attacks when all an attacker has to do is buy the account credentials from an exploit broker or something similar. Cool attacks and countermeasures are fun to talk about, but if you want to make the system more secure you need to fix the things that actually matter. Peter.
Current thread:
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH, (continued)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Peter Gutmann (Sep 24)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Jacob Bachmeyer (Sep 24)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Demi Marie Obenour (Sep 25)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Jacob Bachmeyer (Sep 25)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Demi Marie Obenour (Sep 26)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Jacob Bachmeyer (Sep 27)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Demi Marie Obenour (Sep 27)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Jacob Bachmeyer (Sep 27)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Peter Gutmann (Sep 27)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Demi Marie Obenour (Sep 27)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Peter Gutmann (Sep 27)
- Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH Demi Marie Obenour (Sep 27)
- Message not available
- Re: CVE-2023-51767: a bogus CVE in OpenSSH Damien Miller (Sep 24)