RCE vulnerability in OpenSSH: everything you need to know
ID: 3dc9a90c-3ba1-5b1a-8d8d-b6a49ca00141
STIX ID: report--3dc9a90c-3ba1-5b1a-8d8d-b6a49ca00141
Feed Name: Wiz Blog
An unauthenticated remote code execution vulnerability in OpenSSH (CVE-2024-6387, "regreSSHion") arises from a signal-handler race that can invoke async-signal-unsafe functions (e.g., syslog → malloc/free) on glibc-based 32-bit Linux, enabling heap corruption and potential root code execution; exploitation requires distribution- and glibc-specific conditions, has no confirmed in-the-wild usage as of July 1, 2024, and vendors have released patches with recommendations to upgrade and restrict SSH exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
