logo

CVE-2024-6387 & CVE-2024-6409

ID: 03d82195-ad9d-57aa-979b-d71edb04a7db

STIX ID: report--03d82195-ad9d-57aa-979b-d71edb04a7db

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report documents CVE-2024-6387: a race condition in sshd where the SIGALRM handler calls non-async-signal-safe functions (such as `syslog` → `malloc()`/`free()`), enabling an unauthenticated remote attacker to perform crafted public-key parsing and timed signals to achieve root remote code execution on glibc-based Linux systems; exploitation requires ~10,000 attempts and several hours (3–8h) given default `LoginGraceTime`, `MaxStartups`, and ASLR, and the report includes example malformed requests and network traffic used during exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.