logo

Nasty regreSSHion bug in OpenSSH puts around 700K Linux boxes at risk

ID: 037c1b5c-1283-583b-b948-0a0aa4f62aa7

STIX ID: report--037c1b5c-1283-583b-b948-0a0aa4f62aa7

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-07-01

Date Updated: 2026-04-26

Author: Connor Jones

...
...

RegreSSHion (CVE-2024-6387): a regression in OpenSSH's sshd introduces a remote race condition that can allow unauthenticated remote code execution and potential root takeover on many glibc-based Linux systems; Qualys estimates roughly 700,000 internet-facing instances could be feasibly exploited, exploitation is challenging (requiring many parallel attempts and hours) but a fix is included in OpenSSH 9.8 and vendors (e.g., Ubuntu, NixOS) have released or are releasing patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.