logo

OpenSSH regreSSHion CVE-2024-6387 Vulnerability: Exploitation & Mitigation

ID: 8ce9de0a-8bb0-531c-a8de-33d505e9b842

STIX ID: report--8ce9de0a-8bb0-531c-a8de-33d505e9b842

Feed Name: Resources-2

Threat Score
78/100

Date Published: 2024-07-01

Date Updated: 2026-07-22

Author: [email protected] (Suleyman Ozarslan, PhD)

...
...

CVE-2024-6387 (“regreSSHion”) is a critical OpenSSH regression affecting glibc-based Linux systems that can enable unauthenticated remote code execution as root via a signal-handler race condition; Qualys reports roughly 14 million potentially vulnerable servers. Affected builds include a regression introduced in OpenSSH 8.5p1 (notably 8.5p1–9.7p1 and older unpatched releases); vendors have published fixes and recommended mitigations (apply patches, restrict SSH access, adjust LoginGraceTime) to prevent full system compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.