Upstream does not consider this a bug underlying in OpenSSH and does not
intent to address it in OpenSSH. Additionally, this attack was not demonstrated
against stock OpenSSH, and has never been demonstrated to be exploitable in a real
software configuration.
https://security-tracker.debian.org/tracker/CVE-2023-51767
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059393
https://bugzilla.mindrot.org/show_bug.cgi?id=3656#c1