CVE-2024-6387 & CVE-2024-6409
ID: 03d82195-ad9d-57aa-979b-d71edb04a7db
STIX ID: report--03d82195-ad9d-57aa-979b-d71edb04a7db
Feed Name: Zscaler Security Research Blog
This report documents CVE-2024-6387: a race condition in sshd where the SIGALRM handler calls non-async-signal-safe functions (such as `syslog` → `malloc()`/`free()`), enabling an unauthenticated remote attacker to perform crafted public-key parsing and timed signals to achieve root remote code execution on glibc-based Linux systems; exploitation requires ~10,000 attempts and several hours (3–8h) given default `LoginGraceTime`, `MaxStartups`, and ASLR, and the report includes example malformed requests and network traffic used during exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
