CVE-2024-6387: Critical Remote Code Execution Vulnerability in OpenSSH
ID: 77f54b75-ad51-525e-9704-c9cb02678378
STIX ID: report--77f54b75-ad51-525e-9704-c9cb02678378
Feed Name: Arctic Wolf
**OpenSSH CVE-2024-6387 advisory:** OpenSSH disclosed a signal-handler race vulnerability that can allow unauthenticated RCE as root on glibc-based Linux systems; exploitation is complex, has been demonstrated only on 32-bit systems to date, and there are no known in-the-wild incidents. The report provides distribution-specific patch guidance (upgrade to fixed OpenSSH packages where available), recommends temporary mitigations (set `LoginGraceTime 0`, use fail2ban/firewall blocklists), and cautions about operational impacts of mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
