CVE-2024-6387

Aliases:DEBIAN-CVE-2024-6387RHSA-2024:4312RHSA-2024:4340RHSA-2024:4389ALPINE-CVE-2024-6387
Modified
Published: 01 Jul 2024, 12:37
Last modified:01 Sept 2026, 11:07

Vulnerability Summary

Overall Risk (default)
high
62/100
CVSS Score
8.1 HIGH
v3.1 (cve.org)
EPSS Score
99.51% CRITICAL
100% probability +73.63%
KEV
Not listed
Ransomware
No reports
Public exploits
9 found
Dark Web
Not detected

Timeline

01 Jul 2024, 12:37
Published
Vulnerability first disclosed
01 Sept 2026, 11:07
Last Modified
Vulnerability information updated

Description

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 99.51% Percentile: 100%

Techniques & Countermeasures

  • CWE-364Signal Handler Race Condition

    The product uses a signal handler that introduces a race condition.

  • CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

    The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Affected Systems

  • almalinuxalmalinux

    9.0

  • amazonamazon_linux

    2023.0

  • alpineopenssh

    ≥ 8.6, < 9.1_p1-r6 | ≥ 8.6, < 9.3_p2-r2 | ≥ 8.6, < 9.6_p1-r1 | ≥ 8.6, < 9.7_p1-r4 | ≥ 8.6, < 9.8_p1-r0 | ≥ 8.6, < 9.8_p1-r0 | ≥ 8.6, < 9.8_p1-r0 | ≥ 8.6, < 9.8_p1-r0

  • applemacos

    ≥ 12.0, < 12.7.6 | ≥ 13.0, < 13.6.8 | ≥ 14.0, < 14.6

  • aristaeos

    ≥ 4.32.0, ≤ 4.32.1f

  • canonicalubuntu_linux

    23.10 | 24.04 | 22.04 | 22.10 | 23.04

  • debianopenssh

    < 1:9.2p1-2+deb12u3 | < 1:9.7p1-7 | < 1:9.7p1-7

  • debiandebian_linux

    12.0

  • freebsdfreebsd

    13.2 | 13.2:p1 | 13.2:p10 | 13.2:p11 | 13.2:p2 | 13.2:p3 | 13.2:p4 | 13.2:p5 | 13.2:p6 | 13.2:p7 | 13.2:p8 | 13.2:p9 | 13.3 | 13.3:p1 | 13.3:p2 | 13.3:p3 | 14.0 | 14.0:beta5 | 14.0:p1 | 14.0:p2 | 14.0:p3 | 14.0:p4 | 14.0:p5 | 14.0:p6 | 14.0:p7 | 14.0:rc3 | 14.0:rc4-p1 | 14.1 | 14.1:p1

  • netapp500f_firmware

    na

  • netapp8300_firmware

    na

  • netapp8700_firmware

    na

  • netappa150_firmware

    na

  • netappa1k_firmware

    na

  • netappa220_firmware

    na

  • netappa250_firmware

    na

  • netappa400_firmware

    na

  • netappa70_firmware

    na

  • netappa700s_firmware

    na

  • netappa800_firmware

    na

  • netappa90_firmware

    na

  • netappa900_firmware

    na

  • netappa9500_firmware

    na

  • netappactive_iq_unified_manager

    na

  • netappbootstrap_os

    na

  • netappc190_firmware

    na

  • netappc250_firmware

    na

  • netappc400_firmware

    na

  • netappc800_firmware

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0.0, ≤ 11.70.2

  • netappfas2720_firmware

    na

  • netappfas2750_firmware

    na

  • netappfas2820_firmware

    na

  • netappontap

    9

  • netappontap_select_deploy_administration_utility

    na

  • netappontap_tools

    9 | 10

  • netbsdnetbsd

    ≤ 10.0.0

  • openbsdopenssh

    < 4.4 | ≥ 8.6, ≤ 9.8 | 4.4 | 8.5:p1 | 8.6

  • redhatenterprise_linux

    9.0

  • redhatenterprise_linux_eus

    9.4

  • redhatenterprise_linux_for_arm_64

    9.0_aarch64

  • redhatenterprise_linux_for_arm_64_eus

    9.4_aarch64

  • redhatenterprise_linux_for_ibm_z_systems

    9.0_s390x

  • redhatenterprise_linux_for_ibm_z_systems_eus

    9.4_s390x

  • redhatenterprise_linux_for_power_little_endian

    9.0_ppc64le

  • redhatenterprise_linux_for_power_little_endian_eus

    9.4_ppc64le

  • redhatenterprise_linux_server_aus

    9.4

  • redhatopenshift_container_platform

    4.0

  • redhatopenssh

    < 0:8.7p1-38.el9_4.1 | < 0:8.7p1-30.el9_2.4 | < 0:8.7p1-12.el9_0.1

  • redhatopenssh-askpass

    < 0:8.7p1-38.el9_4.1 | < 0:8.7p1-30.el9_2.4 | < 0:8.7p1-12.el9_0.1

Showing first 50 affected entries in server-rendered view.

References (88)