logo

CVE-2024-6387

ID: 3522c635-eba5-5704-b108-252edb7e6694

STIX ID: report--3522c635-eba5-5704-b108-252edb7e6694

Feed Name: Arctic Wolf Blog

Threat Score
60/100

Date Published: 2024-07-02

Date Updated: 2026-04-27

...
...

OpenSSH released fixes for CVE-2024-6387, a signal-handler race condition in sshd on glibc-based Linux that can permit unauthenticated RCE as root; exploitation is complex (requiring prolonged connections and distro-specific knowledge), has only been demonstrated on 32-bit systems, and no in-the-wild exploitation has been reported. The bulletin recommends upgrading OpenSSH per distribution advisories, or applying mitigations such as setting LoginGraceTime to 0 and using blocking solutions like fail2ban until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.