Comment 5 for bug 2052328

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

I believe this issue is caused by a bad backport in Oracle's 8.0p1-19.el8_9.2 package. I think their fix for CVE-2023-48795 isn't properly adding <email address hidden> to their KEX. Downgrading the Ubuntu package works around the problem as that prevents the client from offering <email address hidden>.