How to Respond: OpenSSH Vulnerability CVE-2024-6387 | UpGuard
ID: 4a115bdb-9d5c-507d-8641-f057f8e764d4
STIX ID: report--4a115bdb-9d5c-507d-8641-f057f8e764d4
Feed Name: UpGuard Blog
Threat Score
CVE-2024-6387 is a high-severity OpenSSH regression impacting 32-bit Linux systems using glibc that can allow unauthenticated remote code execution as root via a signal-handler race condition (CVSS 8.1). The advisory recommends immediate patching to OpenSSH 9.8p1, offers temporary mitigations (e.g., LoginGraceTime=0 and network restrictions), and provides detection guidance through UpGuard; exploitation is technically complex and no public PoC is reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
