CVE-2024-6387

high
Published 2024-07-03 ยท Modified 2024-07-04
CVSS v3
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.1

Description

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

Predictions

Exploit likelihood
100%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-52269 remote linux
Milad karimi ยท 2025-04-22

OpenSSH server (sshd) 9.8p1 - Race Condition

Source code queued for fetch โ€” refresh in a moment.

OS impact

almalinux AlmaLinux Affected 1 release
VersionStatusFixed in
9.0 Affected โ€”
freebsd FreeBSD Affected 5 releases
VersionStatusFixed in
14.1 Affected โ€”
14.0 Affected โ€”
13.3 Affected โ€”
13.2 Affected โ€”
โ€” Affected โ€”
macos macOS Affected 1 release
VersionStatusFixed in
โ€” Affected 12.7.6
suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
ubuntu Ubuntu Affected 5 releases
VersionStatusFixed in
24.04 Affected โ€”
23.10 Affected โ€”
23.04 Affected โ€”
22.10 Affected โ€”
22.04 Affected โ€”
debian Debian Mixed 6 releases
VersionStatusFixed in
trixie Fixed 1:9.7p1-7
sid Fixed 1:9.7p1-7
forky Fixed 1:9.7p1-7
bullseye Fixed 0
bookworm Fixed 1:9.2p1-2+deb12u3
12.0 Affected โ€”
redhat Red Hat Mixed 4 releases
VersionStatusFixed in
9.4 Affected โ€”
9.0_aarch64 Affected โ€”
9.0 Affected โ€”
9 Fixed โ€”
arch Arch Fixed 1 release
VersionStatusFixed in
โ€” Fixed 9.8p1-1

Application impact

VendorProductVersionsFixed
openbsdopenssh8.6
openbsdopenssh4.4
openbsdopenssh8.5
openbsdopenssh{"endExcluding":"4.4"}4.4
redhat redhatopenshift_container_platform4.0
netappactive_iq_unified_manager-
netappe-series_santricity_os_controller{"startIncluding":"11.0.0","endIncluding":"11.70.2"}
netappontap9
netappontap_select_deploy_administration_utility-
netappontap_tools9
netappontap_tools10

References

CWEs

CWE-364 CWE-362

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.