logo

'RegreSSHion' Bug Threatens Takeover of Millions of Linux Systems

ID: ac13747d-ac9b-51f3-8259-4e2e87b89e25

STIX ID: report--ac13747d-ac9b-51f3-8259-4e2e87b89e25

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-07-01

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

Qualys TRU disclosed CVE-2024-6387 ('RegreSSHion'), an unauthenticated signal-handler race condition in OpenSSH's sshd that can allow remote code execution as root on glibc-based Linux systems; researchers estimate over 14 million Internet-exposed servers may be vulnerable, the flaw was a regression of a 2006 fix, has a CVSS ~8.1, is noisy and requires many attempts to exploit, and Qualys/maintainers published fixes (upgrade to OpenSSH 9.8p1 or apply advisory patches) with mitigation advice such as network controls, segmentation, log monitoring for IoCs, and intrusion detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.