LIVE MONITORING
High Advisory CVE-2024-6387

High: OpenSSH RegreSSHion Vulnerability

Affected Systems

OpenSSH 8.5p1 through 9.7p1

A race condition in OpenSSH’s signal handler allows unauthenticated remote code execution as root on glibc-based Linux systems. This is a regression of a vulnerability originally patched in 2006.

Mitigation Steps

  1. Update OpenSSH to 9.8p1 or later
  2. Set LoginGraceTime to 0 as temporary mitigation
  3. Restrict SSH access with firewall rules