USN-6892-1: OpenSSH remote code execution (regreSSHion)
A signal handler race condition in the OpenSSH server carries a risk of unauthenticated RCE as root.
A signal handler race condition in the OpenSSH server carries a risk of unauthenticated RCE as root.
The CVE-2024-6387 (regreSSHion) vulnerability in the OpenSSH sshd service stems from a race condition in the signal handler. Under certain conditions, remote, unauthenticated code execution as root is possible.
glibc-based OpenSSH versions 8.5p1 – 9.7p1. The version in the Ubuntu 22.04 LTS repositories is affected.
sudo apt upgrade openssh-serverLoginGraceTime 0 (NOTE: increases DoS risk)The kernel update released for Ubuntu 24.04 LTS addresses a use-after-free vulnerability in the nf_tables component.
Bulk security patches for the OpenSSL, curl, sudo and systemd packages were published this month.
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.