High SEVERITY — Vulnerability

USN-6892-1: OpenSSH remote code execution (regreSSHion)

A signal handler race condition in the OpenSSH server carries a risk of unauthenticated RCE as root.

Platform
Ubuntu Server
Version
22.04 LTS / Jammy Jellyfish
CVE Record
CVE-2024-6387
CVSS Score
8.1/10
Advisory
USN-6892-1
Published
14 July 2026
Views
6
Primary source: Review the official advisory at ubuntu.com Kaynağa Git

Summary

The CVE-2024-6387 (regreSSHion) vulnerability in the OpenSSH sshd service stems from a race condition in the signal handler. Under certain conditions, remote, unauthenticated code execution as root is possible.

Affected Systems

glibc-based OpenSSH versions 8.5p1 – 9.7p1. The version in the Ubuntu 22.04 LTS repositories is affected.

Recommended Actions

  • Update the package: sudo apt upgrade openssh-server
  • Temporary mitigation: LoginGraceTime 0 (NOTE: increases DoS risk)
  • Restrict SSH access via IP restrictions on the FortiGate firewall
openssh-server openssh-client

Ubuntu Server — Related Advisories

VIEW ALL →