regreSSHion: critical OpenSSH vulnerability
Summary
Qualys analyses CVE-2024-6387, a reintroduced race condition in the OpenSSH server with possible remote code execution. CVE-2024-6387 affects the OpenSSH server and was named regreSSHion. Qualys demonstrated the possibility of unauthenticated remote code execution on glibc-based Linux.
Ideas
- A signal handler executed functions that are not async-signal-safe during the login timeout.
- An earlier security fix was lost through later code changes.
- The attack needs repeated connection attempts and precise timing.
- Address space randomisation makes exploitation harder but does not remove the vulnerability.
- Internet-exposed SSH services increase the operational risk immediately.
Insights
- Regression tests must preserve fixed security root causes, not just visible symptoms.
- Signal handlers form a small, particularly error-prone execution environment.
- Difficult exploitation does not justify delay for reachable root services.
Facts
- OpenSSH 9.8p1 contained the published fix.
Recommendations
- Install your distribution's fixed packages without unnecessary delay.
- Reduce SSH exposure and monitor unusually high numbers of aborted login attempts.
References
Links to the original source and the Web Archive open in a new tab.