Nasty regreSSHion bug in OpenSSH puts around 700K Linux boxes at risk
ID: 037c1b5c-1283-583b-b948-0a0aa4f62aa7
STIX ID: report--037c1b5c-1283-583b-b948-0a0aa4f62aa7
Feed Name: The Register (Security)
RegreSSHion (CVE-2024-6387): a regression in OpenSSH's sshd introduces a remote race condition that can allow unauthenticated remote code execution and potential root takeover on many glibc-based Linux systems; Qualys estimates roughly 700,000 internet-facing instances could be feasibly exploited, exploitation is challenging (requiring many parallel attempts and hours) but a fix is included in OpenSSH 9.8 and vendors (e.g., Ubuntu, NixOS) have released or are releasing patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
