CVE-2024-6387: regreSSHion
A signal handler race condition in OpenSSH's server (sshd), reintroducing a vulnerability originally fixed in 2006 (CVE-2006-5051). If a client fails to authenticate within the configured login grace time, sshd's SIGALRM handler calls functions that are not safe to call from a signal handler, and winning the resulting race lets an unauthenticated remote attacker corrupt memory and achieve code execution as root.
View the authoritative record on NVD ↗Affected software
- OpenSSH 8.5p1 through 9.7p1 on glibc-based Linux systems
How it's exploited
Repeatedly open connections to sshd and let them time out at the login grace period boundary, racing the async-signal-unsafe cleanup code the SIGALRM handler runs; winning the race (typically after thousands of attempts over several hours) corrupts memory in a way that leads to remote code execution as root, no valid credentials required.
Severity
CVE-2024-6387 carries a CVSS 3.1 base score of 8.1, rated High. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2024-6387 is categorized under CWE-364, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Upgrade to OpenSSH 9.8p1 or later, or apply the vendor-backported fix; where an immediate upgrade is not possible, reduce LoginGraceTime as a partial mitigation.
Frequently asked questions
What is CVE-2024-6387?
A signal handler race condition in OpenSSH's server (sshd), reintroducing a vulnerability originally fixed in 2006 (CVE-2006-5051). If a client fails to authenticate within the configured login grace time, sshd's SIGALRM handler calls functions that are not safe to call from a signal handler, and winning the resulting race lets an unauthenticated remote attacker corrupt memory and achieve code execution as root.
How severe is CVE-2024-6387?
CVE-2024-6387 has a CVSS 3.1 base score of 8.1 out of 10, rated High.
What software is affected by CVE-2024-6387?
CVE-2024-6387 affects OpenSSH 8.5p1 through 9.7p1 on glibc-based Linux systems.
How do you fix CVE-2024-6387?
Upgrade to OpenSSH 9.8p1 or later, or apply the vendor-backported fix; where an immediate upgrade is not possible, reduce LoginGraceTime as a partial mitigation.
Where is the authoritative record for CVE-2024-6387?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2024-6387 at https://nvd.nist.gov/vuln/detail/CVE-2024-6387, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest