Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-6387— Openssh: regresshion - race condition in ssh allows rce/dos

Quick assessment

Affected
CVE-2024-6387
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenSSH(OpenBSD Secure Shell)是加拿大OpenBSD计划组的一套用于安全访问远程计算机的连接工具。该工具是SSH协议的开源实现,支持对所有的传输进行加密,可有效阻止窃听、连接劫持以及其他网络级的攻击。 OpenSSH 存在安全漏洞,该漏洞源于信号处理程序中存在竞争条件,攻击者利用该漏洞可以在无需认证的情况下远程执行任意代码并获得系统控制权。

CVSS 8.1 · High EPSS 99.51% · P100

Public Exploits 1

ExploitDB · 1 EDB-52269 [remote]

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 17

VendorProduct Version RangeStatus
None None 8.5p1≤ 9.7p1 affected
Red Hat Red Hat Ceph Storage 5 any unaffected
Red Hat Red Hat Ceph Storage 6 any unaffected
Red Hat Red Hat Ceph Storage 7 any unaffected
Red Hat Red Hat Enterprise Linux 10 any unaffected
Red Hat Red Hat Enterprise Linux 6 any unaffected
Red Hat Red Hat Enterprise Linux 7 any unaffected
Red Hat Red Hat Enterprise Linux 8 any unaffected
Red Hat Red Hat Enterprise Linux 9 0:8.7p1-38.el9_4.1< * unaffected
0:8.7p1-38.el9_4.1< * unaffected
Red Hat Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions 0:8.7p1-12.el9_0.1< * unaffected
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support 0:8.7p1-30.el9_2.4< * unaffected
Red Hat Red Hat OpenShift Container Platform 4 any affected
Red Hat Red Hat OpenShift Container Platform 4.13 413.92.202407091321-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.14 414.92.202407091253-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.15 415.92.202407091355-0< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.16 416.94.202407081958-0< * unaffected

I. Basic Information for CVE-2024-6387

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Openssh: regresshion - race condition in ssh allows rce/dos
Source: CVE Program / CVE List V5
Vulnerability Description
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
信号处理例程中的竞争条件
Source: CVE Program / CVE List V5
Vulnerability Title
OpenSSH 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenSSH(OpenBSD Secure Shell)是加拿大OpenBSD计划组的一套用于安全访问远程计算机的连接工具。该工具是SSH协议的开源实现,支持对所有的传输进行加密,可有效阻止窃听、连接劫持以及其他网络级的攻击。 OpenSSH 存在安全漏洞,该漏洞源于信号处理程序中存在竞争条件,攻击者利用该漏洞可以在无需认证的情况下远程执行任意代码并获得系统控制权。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 8.5p1 ~ 9.7p1 -
Red Hat Red Hat Enterprise Linux 9 0:8.7p1-38.el9_4.1 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:8.7p1-38.el9_4.1 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions 0:8.7p1-12.el9_0.1 ~ * cpe:/a:redhat:rhel_e4s:9.0::appstream
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support 0:8.7p1-30.el9_2.4 ~ * cpe:/a:redhat:rhel_eus:9.2::appstream
Red Hat Red Hat OpenShift Container Platform 4.13 413.92.202407091321-0 ~ * cpe:/a:redhat:openshift:4.13::el8
Red Hat Red Hat OpenShift Container Platform 4.14 414.92.202407091253-0 ~ * cpe:/a:redhat:openshift:4.14::el8
Red Hat Red Hat OpenShift Container Platform 4.15 415.92.202407091355-0 ~ * cpe:/a:redhat:openshift:4.15::el8
Red Hat Red Hat OpenShift Container Platform 4.16 416.94.202407081958-0 ~ * cpe:/a:redhat:openshift:4.16::el9
Red Hat Red Hat Ceph Storage 5 - cpe:/a:redhat:ceph_storage:5
Red Hat Red Hat Ceph Storage 6 - cpe:/a:redhat:ceph_storage:6
Red Hat Red Hat Ceph Storage 7 - cpe:/a:redhat:ceph_storage:7
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2024-6387

# POC Description Source Link Shenlong Link
1 a signal handler race condition in OpenSSH's server (sshd) https://github.com/zgzhang/cve-2024-6387-poc POC Details
2 None https://github.com/acrono/cve-2024-6387-poc POC Details
3 None https://github.com/lflare/cve-2024-6387-poc POC Details
4 Spirit - Network Pentest Tools CVE-2024-6387 https://github.com/theaog/spirit POC Details
5 None https://github.com/shyrwall/cve-2024-6387-poc POC Details
6 None https://github.com/getdrive/CVE-2024-6387-PoC POC Details
7 SSHd cve-2024-6387-poc https://github.com/FerasAlrimali/CVE-2024-6387-POC POC Details
8 None https://github.com/passwa11/cve-2024-6387-poc POC Details
9 None https://github.com/jack0we/CVE-2024-6387 POC Details
10 CVE-2024-6387_Check is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH https://github.com/xaitax/CVE-2024-6387_Check POC Details
11 Bulk Scanning Tool for OpenSSH CVE-2024-6387, CVE-2006-5051 , CVE-2008-4109 and others. https://github.com/bigb0x/CVE-2024-6387 POC Details
12 CLI Tool to Check SSH Servers for Vulnerability to CVE-2024-6387 https://github.com/wiggels/regresshion-check POC Details
13 SSH RCE PoC CVE-2024-6387 https://github.com/3yujw7njai/CVE-2024-6387 POC Details
14 OpenSSH CVE-2024-6387 Vulnerability Checker https://github.com/betancour/OpenSSH-Vulnerability-test POC Details
15 None https://github.com/zgimszhd61/cve-2024-6387-poc POC Details
16 None https://github.com/yya1233/CVE-2024-6387-Updated-SSH-RCE POC Details
17 None https://github.com/muyuanlove/CVE-2024-6387fixshell POC Details
18 Recently, the OpenSSH maintainers released security updates to fix a critical vulnerability that could lead to unauthenticated remote code execution (RCE) with root privileges. This vulnerability, identified as CVE-2024-6387, resides in the OpenSSH server component (sshd), which is designed to listen for connections from client applications. https://github.com/TAM-K592/CVE-2024-6387 POC Details
19 This is a POC I wrote for CVE-2024-6387 https://github.com/teamos-hub/regreSSHion POC Details
20 None https://github.com/Maikefee/CVE-2024-6387_Check.py POC Details
21 None https://github.com/ahlfors/CVE-2024-6387 POC Details
22 None https://github.com/Mufti22/CVE-2024-6387-checkher POC Details
23 CVE-2024-6387 exploit https://github.com/thegenetic/CVE-2024-6387-exploit POC Details
24 RCE OpenSSH CVE-2024-6387 Check https://github.com/HadesNull123/CVE-2024-6387_Check POC Details
25 This script, created by R4Tw1z, is designed to scan IP addresses to check if they are running a potentially vulnerable version of OpenSSH. The tool leverages multi-threading to optimize scanning performance and handle multiple IP addresses concurrently. https://github.com/R4Tw1z/CVE-2024-6387 POC Details
26 This Python script exploits a remote code execution vulnerability (CVE-2024-6387) in OpenSSH. https://github.com/d0rb/CVE-2024-6387 POC Details
27 None https://github.com/oliferFord/CVE-2024-6387-SSH-RCE POC Details
28 Used to detect ssh servers vulnerable to CVE-2024-6387. Shameless robbery from https://github.com/bigb0x/CVE-2024-6387 using ChatGPT to translate the code to PHP. https://github.com/CiderAndWhisky/regression-scanner POC Details
29 Script for checking CVE-2024-6387 (regreSSHion) https://github.com/shamo0/CVE-2024-6387_PoC POC Details
30 CVE-2024-6387-nmap https://github.com/paradessia/CVE-2024-6387-nmap POC Details
AI-Generated POC Verified env Premium
Reproduced successfully in a real sandbox · Below is the actual recording of building the environment and exploiting the vulnerability.
Reproduction recording is a Pro+ exclusive
Watch the full sandbox build + live exploit recording for this CVE. Limited-time ¥499/mo.
Upgrade to Pro+
claude_code · 4603 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2024-6387

请登录查看更多情报信息。

Patches & Fixes for CVE-2024-6387 (1)

Vendor Advisories for CVE-2024-6387 (18)

Mailing List Discussions for CVE-2024-6387 (32)

Security Blog Posts for CVE-2024-6387 (4)

News Coverage for CVE-2024-6387 (2)

Other References for CVE-2024-6387 (15)

IV. Related Vulnerabilities

V. Comments for CVE-2024-6387

No comments yet


Leave a comment