logo

RegreSSHion vulnerability CVE-2024-6387: Overview, detection, and remediation

ID: b2f913b1-3f21-572f-9c73-7f69d33318cb

STIX ID: report--b2f913b1-3f21-572f-9c73-7f69d33318cb

Feed Name: Datadog Security Labs

Threat Score
70/100

Date Published: 2024-07-01

Date Updated: 2026-04-27

...
...

Qualys disclosed CVE-2024-6387 ("regreSSHion"), a pre-auth remote code execution in OpenSSH server (sshd) caused by a race condition in the SIGALRM handler invoking async-unsafe functions like syslog(), reintroducing a regression from a 2006 patch; exploitation can yield a root shell but requires extensive retries (~10,000 attempts) and is architecture-dependent (e.g., harder on amd64 due to ASLR). The advisory lists affected versions (notably 8.5p1–<9.8p1 and older unpatched releases), recommends upgrading to OpenSSH 9.8/9.8p1 (or setting loginGraceTime=0 as a stopgap with DoS risk), and provides detection guidance and Datadog-specific queries for identifying vulnerable hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.