OpenSSH: race condition in sshd allows remote code execution

https://stackdiary.com/openssh-race-condition-in-sshd-allows-remote-code-execution/

A severe vulnerability in OpenSSH, dubbed "regreSSHion" (CVE-2024-6387), has been discovered by the Qualys Threat Research Unit, potentially exposing

104 points · 9 comments · view on lemmy.world

9 Comments

recapitated@lemmy.world · 61 pts · 2y (1 reply)

I always use my ssh server for remote code execution.

m88youngling@slrpnk.net · 21 pts · 2y

technically the truth!

lemmyvore@feddit.nl · 17 pts · 2y (5 replies)

Last I read about it it required connecting for 6-7 hours continuously on 32bit systems, and it's unknown how long it would take on 64bit.

tmpod@lemmy.pt · 3 pts · 2y (4 replies)

Yeah, exactly. Very impracticable.

andrew@radiation.party · 5 pts · 2y (2 replies)

But, eventually exploitable is still a pretty major concern for anybody who has systems running longer than a few days at a time.

tmpod@lemmy.pt · 3 pts · 2y

True, an RCE is always a serious thing. Just saying it's not exactly catastrophic like others have been more so.

whereisk@lemmy.world · 2 pts · 2y

I can’t imagine any system of influence running an exposed ssh without some further protection from connection abuse like fail2ban.

Midnight1938@reddthat.com · 1 pts · 2y

Reminds me of the node-ip guy making thn repo read only because of amateur researchers filling up cve s

tmpod@lemmy.pt · 10 pts · 2y

musl isn't vulnerable, as per https://fosstodon.org/@musl/112711796005712271