s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2024-6387

📛 CVE Title

Openssh: regresshion - race condition in ssh allows rce/dos

Description

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

Overview

State
PUBLISHED
Assigner (CNA)
redhat
CVSS severity
HIGH
CVSS score
CVSS 8.1 / 10 8.1 8.1 / 10
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Effective score
8.1 / 10 HIGH source: CNA overview
MSRC score
8.1 / 10 HIGH MS rating: Critical · Remote Code Execution
CWE(s)
CWE-364
Reserved
2024-06-27
Published
2024-07-01 12:37 UTC
Last updated
2026-05-12 11:39 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/6xxx/CVE-2024-6387.json
Linked Threat
CVE-2024-6387 — Informational Bulletin: Impact of OpenSSH regreSSHion Vulnerability

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2024-07-01 13:15:06 UTC
NVD last modified
2026-05-12 12:17:20 UTC
NVD CVSS v3.1
CVSS 8.1 / 10 8.1 8.1 / 10 HIGH source: secalert@redhat.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability subscore
2.2 / 10
Impact subscore
5.9 / 10
EPSS score
0.6305 (probability of exploitation in next 30 days)
EPSS percentile
98.41% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24

NVD-assigned CWE(s): CWE-364, CWE-362 (differs from the CNA list above)

NVD / KEV / EPSS data refreshed 2026-05-25 01:01 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2024-47981
Assigner
redhat
Published
Jul 1, 2024, 12:37:25 PM
Updated
May 12, 2026, 11:39:26 AM
EUVD base score (CVSS 3.1)
8.1 / 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EUVD-reported EPSS
63.0500
Vendors
Red Hat
Products
Red Hat Enterprise Linux 9 (patch: 0:8.7p1-38.el9_4.1)
Red Hat OpenShift Container Platform 4.15 (patch: 415.92.202407091355-0)
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions (patch: 0:8.7p1-12.el9_0.1)
Red Hat OpenShift Container Platform 4.13 (patch: 413.92.202407091321-0)
Red Hat Enterprise Linux 9.2 Extended Update Support (patch: 0:8.7p1-30.el9_2.4)
Red Hat OpenShift Container Platform 4.16 (patch: 416.94.202407081958-0)
Red Hat OpenShift Container Platform 4.14 (patch: 414.92.202407091253-0)
Aliases
GHSA-2x8c-95vh-gfv4

ENISA description: A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

EUVD references (12)

Microsoft Security Response Center MSRC

Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-12 01:11 UTC (source: CVRF).

MS severity
Critical
Impact
Remote Code Execution
MS CVSS base score
8.1 / 10 (temporal 8.1)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release
2024-Jul
Microsoft remediations / KB articles (9)
Microsoft FAQ (3)

Why is the Red Hat Inc. the assigning CNA (CVE Numbering Authority)?

CVE-2024-6387 is regarding a vulnerability in OppenSSH's server (sshd). Red Hat created this CVE on its behalf.

Is Microsoft Windows vulnerable to CVE-2024-6387?

No, Microsoft Windows is not affected by this vulnerability. Although Windows contains an OpenSSH component, the vulnerable code cannot be exploited or controlled by an adversary.

The race condition used in this exploit is not possible in Windows because of significant differences with login grace timeout handling in the win32-openssh implementation.

Is the update for Azure Kubernetes Service Nodes on Ubuntu Linux currently available?

The security update for Azure Kubernetes Service (AKS) Nodes on Ubuntu Linux is currently being deployed but may not yet be available depending on your resource's deployment region. The deployment will be completed as soon as possible and customers can check the availability of the update here: AKS Release Tracker

Affected products (16)

VendorProductVersionsPlatforms
8.5p1 (affected)
Red Hat Red Hat Enterprise Linux 9 0:8.7p1-38.el9_4.1 (unaffected)
Red Hat Red Hat Enterprise Linux 9 0:8.7p1-38.el9_4.1 (unaffected)
Red Hat Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions 0:8.7p1-12.el9_0.1 (unaffected)
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support 0:8.7p1-30.el9_2.4 (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.13 413.92.202407091321-0 (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.14 414.92.202407091253-0 (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.15 415.92.202407091355-0 (unaffected)
Red Hat Red Hat OpenShift Container Platform 4.16 416.94.202407081958-0 (unaffected)
Red Hat Red Hat Ceph Storage 5
Red Hat Red Hat Ceph Storage 6
Red Hat Red Hat Ceph Storage 7
Red Hat Red Hat Enterprise Linux 10
Red Hat Red Hat Enterprise Linux 6
Red Hat Red Hat Enterprise Linux 7
Red Hat Red Hat Enterprise Linux 8

Affected products — CPE 2.3 (117) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:o:sonicwall:sma_6200_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:sonicwall:sma_6200:-:*:*:*:*:*:*:*
  • cpe:2.3:o:sonicwall:sma_7200_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:sonicwall:sma_7200:-:*:*:*:*:*:*:*
  • cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:23.10:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:lts:*:*:*
  • cpe:2.3:o:almalinux:almalinux:9.0:-:*:*:*:*:*:*
  • cpe:2.3:o:sonicwall:sma_6210_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:sonicwall:sma_6210:-:*:*:*:*:*:*:*
  • cpe:2.3:o:sonicwall:sma_7210_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:sonicwall:sma_7210:-:*:*:*:*:*:*:*
  • cpe:2.3:o:sonicwall:sma_8200v_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:sonicwall:sma_8200v:-:*:*:*:*:*:*:*
  • cpe:2.3:o:sonicwall:sra_ex_7000_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:sonicwall:sra_ex_7000:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:a1k_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:a1k:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:a70_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:a70:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:a90_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:a90:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:a700s_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:a700s:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:8300_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:8300:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:8700_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:8700:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:a400_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:a400:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:c400_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:c400:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:a250:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:500f_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:500f:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:c250_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:c250:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:a800_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:a800:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:c800_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:c800:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:a900_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:a900:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:a9500_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:a9500:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:c190_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:c190:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:a150_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:a150:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:a220_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:a220:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:fas2720_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:fas2720:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:fas2750_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:fas2750:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:fas2820_firmware:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:fas2820:-:*:*:*:*:*:*:*
  • cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
  • cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
  • cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
  • cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
  • cpe:2.3:a:openbsd:openssh:4.4:-:*:*:*:*:*:*
  • cpe:2.3:a:openbsd:openssh:8.5:p1:*:*:*:*:*:*
  • cpe:2.3:a:openbsd:openssh:8.6:-:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_eus:9.4:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:9.4_aarch64:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.4_s390x:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:9.0_ppc64le:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.4_ppc64le:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server_aus:9.4:*:*:*:*:*:*:*
  • cpe:2.3:o:suse:linux_enterprise_micro:6.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:22.10:*:*:*:-:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:lts:*:*:*
  • cpe:2.3:o:amazon:amazon_linux:2023.0:*:*:*:*:*:*:*
  • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
  • cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*
  • cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*
  • cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
  • cpe:2.3:a:netapp:ontap_tools:9:*:*:*:*:vmware_vsphere:*:*
  • cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*
  • cpe:2.3:o:freebsd:freebsd:13.2:-:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.2:p1:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.2:p10:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.2:p11:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.2:p2:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.2:p3:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.2:p4:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.2:p5:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.2:p6:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.2:p7:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.2:p8:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.2:p9:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.3:-:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.3:p1:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.3:p2:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:13.3:p3:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.0:-:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.0:beta5:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.0:p1:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.0:p2:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.0:p3:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.0:p4:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.0:p5:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.0:p6:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.0:p7:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.0:rc3:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.0:rc4-p1:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.1:-:*:*:*:*:*:*
  • cpe:2.3:o:freebsd:freebsd:14.1:p1:*:*:*:*:*:*
  • cpe:2.3:o:netbsd:netbsd:*:*:*:*:*:*:*:*

Vendor references (12)

References embedded in the original CVE record by the assigning CNA.

MITRE references (10) cveawg.mitre.org

Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.

Web references (28)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (93)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Indicators (1)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cve CVE-2024-6387 no local data 2026-05-14 09:34 UTC

Flagged vendors

    Remediations (9)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • rapid7

      aruba-aos-cx-cve-2024-6387

      2026-06-03 22:11 UTC
    • web:blog.qualys.com

      CVE-2024-6387 exploit in OpenSSH poses remote unauthenticated code execution risks. Find out which versions are vulnerable and how to protect your systems.

      2026-05-17 12:56 UTC
    • web:nvd.nist.gov

      Description A security regression ( CVE -2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

      2026-05-17 12:56 UTC
    • web:www.huntress.com

      The CVE-2024-6387 vulnerability was publicly disclosed on July 1, 2024 . It was discovered by security researcher Enguerran Gillier, who reported it to the OpenSSH project. The flaw was the result of a code change made to fix a previous, less severe vulnerability ( CVE -2023-51385), accidentally creating this far more dangerous one. This highlights how even well-intentioned fixes can sometimes ...

      2026-05-17 12:56 UTC
    • web:www.oligo.security

      Apply the fix available in the latest OpenSSH release. Workaround: To patch both vulnerabilities ( CVE-2024-6387 , CVE - 2024 -6409) have a quick patch . Set LoginGraceTime 0 in /etc/ssh/sshd_config and do a systemctl restart sshd. If upgrading is not possible, a temporary workaround is to set LoginGraceTime to 0 in the OpenSSH configuration file.

      2026-05-17 12:56 UTC
    • web:www.penligent.ai

      CVE-2024-6387 (regreSSHion) returned to the spotlight after being added to CISA's Known Exploited Vulnerabilities catalog. This guide explains what the bug is, why exploitation signals matter more than hype, how to verify exposure across Linux distributions, and how to patch , mitigate, and prove remediation with auditable evidence.

      2026-05-17 12:56 UTC
    • web:www.picussecurity.com

      CVE-2024-6387 regreSSHion vulnerability allows for RCE in OpenSSH, impacting millions of servers. Learn about its critical risks and immediate mitigation steps.

      2026-05-17 12:56 UTC
    • web:www.redteamnews.com

      These flaws represent the first major remote code execution vulnerabilities in OpenSSH in nearly two decades, with CVE-2024-6387 allowing unauthenticated attackers to potentially gain root privileges. Security teams should prioritize patching and mitigation given the active exploitation observed in the wild. Technical Analysis of the ...

      2026-05-17 12:56 UTC
    • web:www.suse.com

      Secure your Linux systems from CVE-2024-6387 . Stay ahead of potential threats with the latest security updates from SUSE.

      2026-05-17 12:56 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2024-6387.json.

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6387",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-02T13:18:34.695298Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-02T13:18:46.662Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-04-24T18:35:27.934Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://www.vicarius.io/vsociety/posts/regresshion-an-openssh-regression-error-cve-2024-6387"
              },
              {
                "url": "https://www.exploit-db.com/exploits/52269"
              },
              {
                "url": "https://packetstorm.news/files/id/190587/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/01/12"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/01/13"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/02/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/03/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/03/11"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/03/2"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/03/3"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/03/4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/03/5"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/04/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/04/2"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/08/2"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/08/3"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/09/2"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/09/5"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/10/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/10/2"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/10/3"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/10/4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/10/6"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/11/1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/11/3"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/23/4"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/23/6"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/28/2"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://www.openwall.com/lists/oss-security/2024/07/28/3"
              },
              {
                "name": "RHSA-2024:4312",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2024:4312"
              },
              {
                "name": "RHSA-2024:4340",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2024:4340"
              },
              {
                "name": "RHSA-2024:4389",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2024:4389"
              },
              {
                "name": "RHSA-2024:4469",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2024:4469"
              },
              {
                "name": "RHSA-2024:4474",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2024:4474"
              },
              {
                "name": "RHSA-2024:4479",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2024:4479"
              },
              {
                "name": "RHSA-2024:4484",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2024:4484"
              },
              {
                "tags": [
                  "vdb-entry",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/security/cve/CVE-2024-6387"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://archlinux.org/news/the-sshd-service-needs-to-be-restarted-after-upgrading-to-openssh-98p1/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://arstechnica.com/security/2024/07/regresshion-vulnerability-in-openssh-gives-attackers-root-on-linux/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server"
              },
              {
                "name": "RHBZ#2294604",
                "tags": [
                  "issue-tracking",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294604"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://explore.alas.aws.amazon.com/CVE-2024-6387.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://forum.vmssoftware.com/viewtopic.php?f=8&t=9132"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2024-002.txt.asc"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/AlmaLinux/updates/issues/629"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/Azure/AKS/issues/4379"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/PowerShell/Win32-OpenSSH/discussions/2248"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/PowerShell/Win32-OpenSSH/issues/2249"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/microsoft/azurelinux/issues/9555"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/openela-main/openssh/commit/e1f438970e5a337a17070a637c1b9e19697cad09"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/oracle/oracle-linux/issues/149"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/rapier1/hpn-ssh/issues/87"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/zgzhang/cve-2024-6387-poc"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.almalinux.org/archives/list/announce@lists.almalinux.org/thread/23BF5BMGFVEVUI2WNVAGMLKT557EU7VY/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-July/000158.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://lists.mindrot.org/pipermail/openssh-unix-dev/2024-July/041431.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://news.ycombinator.com/item?id=40843778"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0010"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://santandersecurityresearch.github.io/blog/sshing_the_masses.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security-tracker.debian.org/tracker/CVE-2024-6387"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240701-0001/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://sig-security.rocky.page/issues/CVE-2024-6387/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://stackdiary.com/openssh-race-condition-in-sshd-allows-remote-code-execution/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://ubuntu.com/security/CVE-2024-6387"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://ubuntu.com/security/notices/USN-6859-1"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.akamai.com/blog/security-research/2024-openssh-vulnerability-regression-what-to-know-and-do"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/19904-security-advisory-0100"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.freebsd.org/security/advisories/FreeBSD-SA-24:04.openssh.asc"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.openssh.com/txt/release-9.8"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.splunk.com/en_us/blog/security/cve-2024-6387-regresshion-vulnerability.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.suse.com/security/cve/CVE-2024-6387.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.theregister.com/2024/07/01/regresshion_openssh/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.apple.com/kb/HT214119"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.apple.com/kb/HT214118"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://support.apple.com/kb/HT214120"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://seclists.org/fulldisclosure/2024/Jul/20"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://seclists.org/fulldisclosure/2024/Jul/18"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://seclists.org/fulldisclosure/2024/Jul/19"
              }
            ],
            "title": "CVE Program Container",
            "x_generator": {
              "engine": "ADPogram 0.0.1"
            }
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "Industrial Edge Management OS (IEM-OS)",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SINAMICS IIoT module",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V1.0 HF1",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SINEMA Remote Connect Server",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.2 SP2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SINUMERIK ONE",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V6.24",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T11:39:26.672Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-446545.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://www.openssh.com/",
              "defaultStatus": "unaffected",
              "packageName": "OpenSSH",
              "repo": "https://anongit.mindrot.org/openssh.git",
              "versions": [
                {
                  "lessThanOrEqual": "9.7p1",
                  "status": "affected",
                  "version": "8.5p1",
                  "versionType": "custom"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:enterprise_linux:9::appstream",
                "cpe:/o:redhat:enterprise_linux:9::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 9",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.7p1-38.el9_4.1",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:enterprise_linux:9::appstream",
                "cpe:/o:redhat:enterprise_linux:9::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 9",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.7p1-38.el9_4.1",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:rhel_e4s:9.0::appstream",
                "cpe:/o:redhat:rhel_e4s:9.0::baseos"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.7p1-12.el9_0.1",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:rhel_eus:9.2::baseos",
                "cpe:/a:redhat:rhel_eus:9.2::appstream"
              ],
              "defaultStatus": "affected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 9.2 Extended Update Support",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "0:8.7p1-30.el9_2.4",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://catalog.redhat.com/software/containers/",
              "cpes": [
                "cpe:/a:redhat:openshift:4.13::el9",
                "cpe:/a:redhat:openshift:4.13::el8"
              ],
              "defaultStatus": "affected",
              "packageName": "rhcos",
              "product": "Red Hat OpenShift Container Platform 4.13",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "413.92.202407091321-0",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://catalog.redhat.com/software/containers/",
              "cpes": [
                "cpe:/a:redhat:openshift:4.14::el8",
                "cpe:/a:redhat:openshift:4.14::el9"
              ],
              "defaultStatus": "affected",
              "packageName": "rhcos",
              "product": "Red Hat OpenShift Container Platform 4.14",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "414.92.202407091253-0",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://catalog.redhat.com/software/containers/",
              "cpes": [
                "cpe:/a:redhat:openshift:4.15::el8",
                "cpe:/a:redhat:openshift:4.15::el9"
              ],
              "defaultStatus": "affected",
              "packageName": "rhcos",
              "product": "Red Hat OpenShift Container Platform 4.15",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "415.92.202407091355-0",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://catalog.redhat.com/software/containers/",
              "cpes": [
                "cpe:/a:redhat:openshift:4.16::el9"
              ],
              "defaultStatus": "affected",
              "packageName": "rhcos",
              "product": "Red Hat OpenShift Container Platform 4.16",
              "vendor": "Red Hat",
              "versions": [
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "416.94.202407081958-0",
                  "versionType": "rpm"
                }
              ]
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:ceph_storage:5"
              ],
              "defaultStatus": "unaffected",
              "packageName": "openssh",
              "product": "Red Hat Ceph Storage 5",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:ceph_storage:6"
              ],
              "defaultStatus": "unaffected",
              "packageName": "openssh",
              "product": "Red Hat Ceph Storage 6",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/a:redhat:ceph_storage:7"
              ],
              "defaultStatus": "unaffected",
              "packageName": "openssh",
              "product": "Red Hat Ceph Storage 7",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:10"
              ],
              "defaultStatus": "unaffected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 10",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:6"
              ],
              "defaultStatus": "unaffected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 6",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:7"
              ],
              "defaultStatus": "unaffected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 7",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:8"
              ],
              "defaultStatus": "unaffected",
              "packageName": "openssh",
              "product": "Red Hat Enterprise Linux 8",
              "vendor": "Red Hat"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Red Hat would like to thank Qualys Threat Research Unit (TRU) (Qualys) for reporting this issue."
            }
          ],
          "datePublic": "2024-07-01T08:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "namespace": "https://access.redhat.com/security/updates/classification/",
                  "value": "Important"
                },
                "type": "Red Hat severity rating"
              }
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-364",
                  "description": "Signal Handler Race Condition",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-11T06:17:03.387Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "name": "RHSA-2024:4312",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2024:4312"
            },
            {
              "name": "RHSA-2024:4340",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2024:4340"
            },
            {
              "name": "RHSA-2024:4389",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2024:4389"
            },
            {
              "name": "RHSA-2024:4469",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2024:4469"
            },
            {
              "name": "RHSA-2024:4474",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2024:4474"
            },
            {
              "name": "RHSA-2024:4479",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2024:4479"
            },
            {
              "name": "RHSA-2024:4484",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2024:4484"
            },
            {
              "tags": [
                "vdb-entry",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/security/cve/CVE-2024-6387"
            },
            {
              "name": "RHBZ#2294604",
              "tags": [
                "issue-tracking",
                "x_refsource_REDHAT"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2294604"
            },
            {
              "url": "https://santandersecurityresearch.github.io/blog/sshing_the_masses.html"
            },
            {
              "url": "https://www.openssh.com/txt/release-9.8"
            },
            {
              "url": "https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-06-27T00:00:00.000Z",
              "value": "Reported to Red Hat."
            },
            {
              "lang": "en",
              "time": "2024-07-01T08:00:00.000Z",
              "value": "Made public."
            }
          ],
          "title": "Openssh: regresshion - race condition in ssh allows rce/dos",
          "workarounds": [
            {
              "lang": "en",
              "value": "The below process can protect against a Remote Code Execution attack by disabling the LoginGraceTime parameter on Red Hat Enterprise Linux 9. However, the sshd server is still vulnerable to a Denial of Service if an attacker exhausts all the connections.\n\n1) As root user, open the /etc/ssh/sshd_config\n2) Add or edit the parameter configuration:\n~~~\nLoginGraceTime 0\n~~~\n3) Save and close the file\n4) Restart the sshd daemon:\n~~~\nsystemctl restart sshd.service\n~~~\n\nSetting LoginGraceTime to 0 disables the SSHD server's ability to drop connections if authentication is not completed within the specified timeout. If this mitigation is implemented, it is highly recommended to use a tool like 'fail2ban' alongside a firewall to monitor log files and manage connections appropriately.\n\nIf any of the mitigations mentioned above is used, please note that the removal of LoginGraceTime parameter from sshd_config is not automatic when the updated package is installed."
            }
          ],
          "x_generator": {
            "engine": "cvelib 1.8.0"
          },
          "x_redhatCweChain": "CWE-364: Signal Handler Race Condition"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2024-6387",
        "datePublished": "2024-07-01T12:37:25.431Z",
        "dateReserved": "2024-06-27T13:41:03.421Z",
        "dateUpdated": "2026-05-12T11:39:26.672Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }