CVE-2024-6387

Description

A security regression (CVE-2006-5051) was discovered in OpenSSHs server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
48.06

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Security Guardium 12.0Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 12.1Windows
Multiple vulnerabilities are fixed in Mac OS - Ventura 13.6.8 (Software Update) - AutoReboot (CVE-2024-27877)Mac
Multiple vulnerabilities are fixed in Mac OS - Monterey 12.7.6 (Software Update) - AutoReboot (CVE-2024-27877)Mac
Multiple vulnerabilities are fixed in Mac OS - Sonoma 14.6 (Software Update) - AutoReboot (CVE-2024-27877)Mac
Multiple vulnerabilities are fixed in Mac OS - Sonoma 14.6.1 (Software Update) - AutoRebootMac
secure shell (SSH) for secure access to remote machines (USN-6859-1) openssh-client_8.9p1-3ubuntu0.10_amd64.debLinux
secure shell (SSH) for secure access to remote machines (USN-6859-1) openssh-client_8.9p1-3ubuntu0.10_i386.debLinux
secure shell (SSH) for secure access to remote machines (USN-6859-1) openssh-client_9.3p1-1ubuntu3.6_amd64.debLinux
secure shell (SSH) for secure access to remote machines (USN-6859-1) openssh-client_9.3p1-1ubuntu3.6_i386.debLinux
secure shell (SSH) for secure access to remote machines (USN-6859-1) openssh-client_9.6p1-3ubuntu13.3_amd64.debLinux
secure shell (SSH) for secure access to remote machines (USN-6859-1) openssh-client_9.6p1-3ubuntu13.3_i386.debLinux
secure shell (SSH) for secure access to remote machines (USN-6859-1) openssh-server_8.9p1-3ubuntu0.10_amd64.debLinux
secure shell (SSH) for secure access to remote machines (USN-6859-1) openssh-server_8.9p1-3ubuntu0.10_i386.debLinux
secure shell (SSH) for secure access to remote machines (USN-6859-1) openssh-server_9.3p1-1ubuntu3.6_amd64.debLinux
secure shell (SSH) for secure access to remote machines (USN-6859-1) openssh-server_9.3p1-1ubuntu3.6_i386.debLinux
secure shell (SSH) for secure access to remote machines (USN-6859-1) openssh-server_9.6p1-3ubuntu13.3_amd64.debLinux
secure shell (SSH) for secure access to remote machines (USN-6859-1) openssh-server_9.6p1-3ubuntu13.3_i386.debLinux
Openssh-clients update (ELSA-2024-12468) openssh-clients-8.7p1-38.0.2.el9.x86_64.rpmLinux
Openssh-askpass update (ELSA-2024-12468) openssh-askpass-8.7p1-38.0.2.el9.x86_64.rpmLinux
Openssh-keycat update (ELSA-2024-12468) openssh-keycat-8.7p1-38.0.2.el9.x86_64.rpmLinux
Openssh-server update (ELSA-2024-12468) openssh-server-8.7p1-38.0.2.el9.x86_64.rpmLinux
Pam_ssh_agent_auth update (ELSA-2024-12468) pam_ssh_agent_auth-0.10.4-5.38.0.2.el9.x86_64.rpmLinux
Openssh update (ELSA-2024-12468) openssh-8.7p1-38.0.2.el9.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update pam_ssh_agent_auth-debuginfo-0.10.4-5.38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update pam_ssh_agent_auth-0.10.4-5.38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update openssh-sk-dummy-debuginfo-8.7p1-38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update openssh-server-debuginfo-8.7p1-38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update openssh-server-8.7p1-38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update openssh-keycat-debuginfo-8.7p1-38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update openssh-keycat-8.7p1-38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update openssh-debugsource-8.7p1-38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update openssh-debuginfo-8.7p1-38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update openssh-clients-debuginfo-8.7p1-38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update openssh-clients-8.7p1-38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update openssh-askpass-debuginfo-8.7p1-38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update openssh-askpass-8.7p1-38.el9_4.1.x86_64.rpmLinux
(RHSA-2024:4312)Important: security update openssh-8.7p1-38.el9_4.1.x86_64.rpmLinux
openssh security update(DSA-5724-1) ssh-askpass-gnome_9.2p1-2+deb12u3_i386.debLinux
openssh security update(DSA-5724-1) ssh-askpass-gnome_9.2p1-2+deb12u3_amd64.debLinux
openssh security update(DSA-5724-1) ssh_9.2p1-2+deb12u3_all.debLinux
openssh security update(DSA-5724-1) openssh-tests_9.2p1-2+deb12u3_i386.debLinux
openssh security update(DSA-5724-1) openssh-tests_9.2p1-2+deb12u3_amd64.debLinux
openssh security update(DSA-5724-1) openssh-sftp-server_9.2p1-2+deb12u3_i386.debLinux
openssh security update(DSA-5724-1) openssh-sftp-server_9.2p1-2+deb12u3_amd64.debLinux
openssh security update(DSA-5724-1) openssh-server_9.2p1-2+deb12u3_i386.debLinux
openssh security update(DSA-5724-1) openssh-server_9.2p1-2+deb12u3_amd64.debLinux
openssh security update(DSA-5724-1) openssh-client_9.2p1-2+deb12u3_i386.debLinux
openssh security update(DSA-5724-1) openssh-client_9.2p1-2+deb12u3_amd64.debLinux
openssh Security Update (ALAS-2024-649) pam_ssh_agent_auth-0.10.4-4.8.amzn2023.0.11.x86_64.rpmLinux
openssh Security Update (ALAS-2024-649) openssh-server-8.7p1-8.amzn2023.0.11.x86_64.rpmLinux
openssh Security Update (ALAS-2024-649) openssh-keycat-8.7p1-8.amzn2023.0.11.x86_64.rpmLinux
openssh Security Update (ALAS-2024-649) openssh-clients-8.7p1-8.amzn2023.0.11.x86_64.rpmLinux
openssh Security Update (ALAS-2024-649) openssh-8.7p1-8.amzn2023.0.11.x86_64.rpmLinux
openssh security update (RLNSA-2024:4312) openssh-server-8.7p1-38.el9_4.1.x86_64.rpmLinux
openssh security update (RLNSA-2024:4312) openssh-keycat-8.7p1-38.el9_4.1.x86_64.rpmLinux
openssh security update (RLNSA-2024:4312) openssh-clients-8.7p1-38.el9_4.1.x86_64.rpmLinux
openssh security update (RLNSA-2024:4312) openssh-askpass-8.7p1-38.el9_4.1.x86_64.rpmLinux
openssh security update (RLNSA-2024:4312) openssh-8.7p1-38.el9_4.1.x86_64.rpmLinux
Pam_ssh_agent_auth update (ELSA-2024-4312) pam_ssh_agent_auth-0.10.4-5.38.0.2.el9_4.1.x86_64.rpmLinux
Openssh-server update (ELSA-2024-4312) openssh-server-8.7p1-38.0.2.el9_4.1.x86_64.rpmLinux
Openssh-keycat update (ELSA-2024-4312) openssh-keycat-8.7p1-38.0.2.el9_4.1.x86_64.rpmLinux
Openssh-clients update (ELSA-2024-4312) openssh-clients-8.7p1-38.0.2.el9_4.1.x86_64.rpmLinux
Openssh-askpass update (ELSA-2024-4312) openssh-askpass-8.7p1-38.0.2.el9_4.1.x86_64.rpmLinux
Openssh update (ELSA-2024-4312) openssh-8.7p1-38.0.2.el9_4.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-server-debuginfo-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-server-config-disallow-rootlogin-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-server-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-helpers-debuginfo-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-helpers-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-fips-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-debugsource-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-debuginfo-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-common-debuginfo-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-common-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-clients-debuginfo-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-clients-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Desktop Applications Module 15-SP6) openssh-askpass-gnome-debugsource-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Desktop Applications Module 15-SP6) openssh-askpass-gnome-debuginfo-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Desktop Applications Module 15-SP6) openssh-askpass-gnome-9.6p1-150600.6.3.1.x86_64.rpmLinux
SUSE-SU-2024:2275-1(Basesystem Module 15-SP6) openssh-9.6p1-150600.6.3.1.x86_64.rpmLinux
Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) Vulnerability (CVE-2024-6387)NCM
Signal Handler Race Condition Vulnerability (CVE-2024-6387)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-611601Mac OS - Ventura 13.7.7 (Software Update) (Auto Reboot)(Deployment-Only)
PATCH-608134Mac OS - Monterey 12.7.6 (Software Update) - AutoReboot (CVE-2024-27877)
PATCH-609043Mac OS - Sonoma 14.7.1 (Software Update) - AutoReboot (Deployment-Only)
PATCH-609043Mac OS - Sonoma 14.7.1 (Software Update) - AutoReboot (Deployment-Only)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234