New regreSSHion OpenSSH RCE bug gives root on Linux servers
ID: aaf162ca-3ea8-55fe-bdfa-ae3a03a94e93
STIX ID: report--aaf162ca-3ea8-55fe-bdfa-ae3a03a94e93
Feed Name: Bleeping Computer
A newly disclosed OpenSSH unauthenticated RCE called "regreSSHion" (CVE-2024-6387) was published by Qualys in May 2024; it stems from a SIGALRM signal handler race in sshd and can allow remote unauthenticated attackers to execute arbitrary code as root on affected glibc-based Linux systems. The flaw impacts OpenSSH versions 8.5p1 up to (but not including) 9.8p1, Qualys confirmed ~700,000 vulnerable instances, exploitation is reported as difficult but possible, and mitigations include upgrading to 9.8p1, restricting SSH access, or setting LoginGraceTime to 0 as a temporary measure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
