PT-2024-4415 · Openssh+11 · Openssh+11

Smartkeyss

·

Published

2006-09-29

·

Updated

2026-05-31

·

CVE-2024-6387

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: OpenSSH versions prior to 9.6p1-alt2, 7.9p1-alt4.gost.p10.1, and 8.9p1.202310-alt3.
Description: A signal handler race condition exists in OpenSSH's server (sshd) when a client does not authenticate within the LoginGraceTime seconds. This can lead to the execution of arbitrary code with root privileges. The issue is a regression of CVE-2006-5051 and affects systems where the signal handler calls functions that are not async-signal-safe, such as syslog(). The vulnerability also includes a remote code execution issue in ssh-agent when using PKCS#11 support (CVE-2023-38408) and a file descriptor leak in runC (CVE-2024-21626).
Recommendations: Upgrade OpenSSH to version 9.6p1-alt2 or later. Upgrade openquantumsafe-openssh to version 8.9p1.202310-alt3 or later. Upgrade openssh-gostcrypto to version 7.9p1-alt4.gost.p10.1 or later. Upgrade runC to the latest version to address the file descriptor leak.

Exploit

Fix

RCE

DoS

Race Condition

Weakness Enumeration

Related Identifiers

ALSA-2021_4368
ALSA-2022_2013
ALSA-2023_2645
ALSA-2023_4412
ALSA-2023_4419
ALSA-2024:4312
ALSA-2024_0606
ALSA-2024_0628
ALSA-2024_0670
ALSA-2024_0748
ALSA-2024_0752
ALSA-2024_1130
ALSA-2024_1150
ALSA-2024_3166
ALSA-2024_4312
ALSA-2025_16880
ALT-PU-2024-17672
ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9505
ALT-PU-2024-9513
AZL-43024
AZL-43030
BDU:2024-04914
BDU:2024-06777
CVE-2024-6387
DSA-5724-1
ELSA-2024-12468
ELSA-2024-4312
FREEBSD-SA-24_04
INFSA-2024_4312
JLSEC-2026-71
MGASA-2024-0250
OESA-2024-1781
OESA-2024-1782
OESA-2024-1783
OESA-2024-1784
OPENSUSE-SU-2024:14088-1
OPENSUSE-SU-2024_2275-1
OPENSUSE-SU-2024_2275-2
RHSA-2006_0697
RHSA-2024:4312
RHSA-2024:4340
RHSA-2024:4389
RHSA-2024_4312
SUSE-SU-2024:2275-1
SUSE-SU-2024:2275-2
SUSE-SU-2024_2275-1
SUSE-SU-2025:20009-1
USN-6859-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Freebsd
Ibm Aix
Linuxmint
Apple Macos
Openssh
Red Hat
Red Os
Suse
Ubuntu