CVE-2024-6387: Critical Remote Code Execution Vulnerability in OpenSSH
ID: 10432b63-5e7b-5a42-b6f5-52cddb13db83
STIX ID: report--10432b63-5e7b-5a42-b6f5-52cddb13db83
Feed Name: Arctic Wolf
**OpenSSH CVE-2024-6387 advisory:** OpenSSH released fixes for CVE-2024-6387, a signal-handler race condition in sshd on glibc-based Linux systems that can enable unauthenticated remote code execution as root; exploitation has been demonstrated only on 32-bit systems, is complex, and no in-the-wild cases have been reported. The advisory includes a distribution-specific table of affected versions and recommendations to upgrade to OpenSSH 9.8 (or distro-updated packages) where available, and offers mitigations such as setting LoginGraceTime to 0 and using blocking solutions like fail2ban as interim measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
