logo

regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server

ID: ac79b936-f077-5ce8-9b6b-029519660b89

STIX ID: report--ac79b936-f077-5ce8-9b6b-029519660b89

Feed Name: Qualys Blog

Threat Score
85/100

Date Published: 2024-07-01

Date Updated: 2026-04-28

Author: Bharat Jogi

...
...

Qualys TRU discloses CVE-2024-6387 (“regreSSHion”), a signal-handler race condition in OpenSSH sshd that permits unauthenticated remote code execution as root on glibc-based Linux systems; Qualys reports widespread exposure (over 14 million potentially vulnerable instances and ~700,000 internet-facing instances in their customer data), identifies affected OpenSSH versions (regression introduced in 8.5p1, fixed in 9.8p1), developed a working exploit (not published), and provides QIDs, mitigations (e.g., set LoginGraceTime to 0), and patch/remediation guidance for customers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.