PT-2024-4415 · Openssh+11 · Openssh+11
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSH versions 8.5p1 through 9.6p1
Description
A race condition exists in the signal handler of the OpenSSH server (
sshd). When a client fails to authenticate within the LoginGraceTime (defaulting to 120 seconds), the SIGALRM handler is invoked asynchronously. This handler calls functions that are not async-signal-safe, such as syslog(), which can lead to the reuse of previously freed memory. A remote unauthenticated attacker can exploit this flaw to execute arbitrary code with root privileges. This issue is a regression of a previous flaw and affects sshd in its default configuration on glibc-based Linux systems.Recommendations
Update OpenSSH server to version 1:9.2p1-2+deb12u3 for Debian stable (bookworm).
Update OpenSSH packages to version 1:9.6p1-3ubuntu13.3 for Ubuntu.
As a temporary mitigation, restrict the use of the
LoginGraceTime parameter or limit access to the sshd service to trusted networks.Exploit
Fix
RCE
DoS
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Freebsd
Ibm Aix
Linuxmint
Apple Macos
Openssh
Red Hat
Red Os
Suse
Ubuntu