OpenSSH bug leaves RHEL 9 and the RHELatives vulnerable
ID: 347f4c40-a2dd-5980-a22d-648ef67e5b2c
STIX ID: report--347f4c40-a2dd-5980-a22d-648ef67e5b2c
Feed Name: The Register (Security)
Threat Score
A new OpenSSH vulnerability (CVE-2024-6409) — a signal-handler race in sshd 8.7p1/8.8p1 — was disclosed by Alexander Peslyak (Solar Designer). The flaw can potentially allow remote code execution in a reduced-privilege sshd process; AlmaLinux has issued a patch, affected Fedora releases are end-of-life, and major supported distributions report limited or no exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
