New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems
ID: 7a8c8eef-f6be-574a-8bf6-2626aebae823
STIX ID: report--7a8c8eef-f6be-574a-8bf6-2626aebae823
Feed Name: The Hacker News
OpenSSH maintainers released patches for CVE-2024-6387 (regreSSHion), a signal-handler race condition in sshd that can allow unauthenticated remote code execution as root on glibc-based Linux systems; Qualys identified ~14 million potentially vulnerable Internet-exposed servers (affecting versions 8.5p1–9.7p1 and certain older releases), exploitation has been demonstrated in lab conditions (notably 32-bit glibc) but requires prolonged, high-volume attempts, vendors including Cisco are impacted, and users are urged to apply patches and restrict SSH exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
