regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server
ID: ac79b936-f077-5ce8-9b6b-029519660b89
STIX ID: report--ac79b936-f077-5ce8-9b6b-029519660b89
Feed Name: Qualys Blog
Qualys TRU discloses CVE-2024-6387 (“regreSSHion”), a signal-handler race condition in OpenSSH sshd that permits unauthenticated remote code execution as root on glibc-based Linux systems; Qualys reports widespread exposure (over 14 million potentially vulnerable instances and ~700,000 internet-facing instances in their customer data), identifies affected OpenSSH versions (regression introduced in 8.5p1, fixed in 9.8p1), developed a working exploit (not published), and provides QIDs, mitigations (e.g., set LoginGraceTime to 0), and patch/remediation guidance for customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
