A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog(). As a consequence of a successful attack, in the worst case scenario, an attacker may be able to perform a remote code execution (RCE) as an unprivileged user running the sshd server.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssh-serverUpgrade openssh-askpassUpgrade openssh-clientsUpgrade opensshUpgrade openssh-keycatUpgrade pam_ssh_agent_auth | Jul 19, 2024 | Jul 8, 2024 |
| Amazon_linux_2023 | — | Upgrade openssh-keycatUpgrade pam_ssh_agent_authUpgrade opensshUpgrade openssh-keycat-debuginfoUpgrade openssh-clientsUpgrade openssh-serverUpgrade openssh-debuginfoUpgrade openssh-debugsourceUpgrade openssh-clients-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-server-debuginfo | Feb 17, 2025 | Jul 8, 2024 |
| Arista Eos | — | Upgrade to a fixed EOS release or apply the available hotfix. As a temporary mitigation, enable SSH service ACLs or disable the SSH login grace time. | Jul 23, 2025 | Jul 8, 2024 |
| F5 Big Ip | — | — | Sep 9, 2024 | Jul 8, 2024 |
| Huawei Euleros 2_0_sp10 | — | Upgrade openssh-clientsUpgrade opensshUpgrade openssh-server | Mar 18, 2025 | Jul 8, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade openssh-serverUpgrade openssh-clientsUpgrade openssh | Oct 9, 2024 | Jul 8, 2024 |
| Huawei Euleros 2_0_sp9 | — | Upgrade openssh-clientsUpgrade openssh-serverUpgrade openssh | Mar 18, 2025 | Jul 8, 2024 |
| Oracle_linux | — | Upgrade openssh-keycatUpgrade openssh-askpassUpgrade pam_ssh_agent_authUpgrade openssh-clientsUpgrade opensshUpgrade openssh-server | Aug 16, 2024 | Jul 8, 2024 |
| Redhat Openshift | — | Upgrade rhcos | Jul 25, 2024 | Jul 8, 2024 |
| Redhat_linux | — | Upgrade openssh-sk-dummy-debuginfoUpgrade openssh-debugsourceUpgrade openssh-serverUpgrade opensshUpgrade openssh-server-debuginfoUpgrade openssh-clients-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-askpass-debuginfoUpgrade openssh-askpassUpgrade openssh-keycat-debuginfoUpgrade openssh-debuginfoUpgrade openssh-keycatUpgrade openssh-clientsUpgrade pam_ssh_agent_auth | Jul 16, 2024 | Jul 8, 2024 |
| Rocky_linux | — | Upgrade openssh-askpassUpgrade pam_ssh_agent_authUpgrade openssh-debugsourceUpgrade openssh-keycat-debuginfoUpgrade openssh-keycatUpgrade opensshUpgrade openssh-serverUpgrade openssh-askpass-debuginfoUpgrade openssh-server-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-clients-debuginfoUpgrade openssh-clientsUpgrade openssh-debuginfo | Jul 16, 2024 | Jul 8, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub