bk99.de entertain the web since 1997

regreSSHion: critical OpenSSH vulnerability

Summary

Qualys analyses CVE-2024-6387, a reintroduced race condition in the OpenSSH server with possible remote code execution. CVE-2024-6387 affects the OpenSSH server and was named regreSSHion. Qualys demonstrated the possibility of unauthenticated remote code execution on glibc-based Linux.

Ideas

  • A signal handler executed functions that are not async-signal-safe during the login timeout.
  • An earlier security fix was lost through later code changes.
  • The attack needs repeated connection attempts and precise timing.
  • Address space randomisation makes exploitation harder but does not remove the vulnerability.
  • Internet-exposed SSH services increase the operational risk immediately.

Insights

  • Regression tests must preserve fixed security root causes, not just visible symptoms.
  • Signal handlers form a small, particularly error-prone execution environment.
  • Difficult exploitation does not justify delay for reachable root services.

Facts

  • OpenSSH 9.8p1 contained the published fix.

Recommendations

  • Install your distribution's fixed packages without unnecessary delay.
  • Reduce SSH exposure and monitor unusually high numbers of aborted login attempts.

References

Read the original article

Search the Web Archive