A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog(). As a consequence of a successful attack, in the worst case scenario, an attacker may be able to perform a remote code execution (RCE) as an unprivileged user running the sshd server.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssh-serverUpgrade opensshUpgrade openssh-clientsUpgrade openssh-askpassUpgrade pam_ssh_agent_authUpgrade openssh-keycat | Jul 19, 2024 | Jul 8, 2024 |
| Amazon_linux_2023 | — | Upgrade openssh-keycatUpgrade pam_ssh_agent_authUpgrade opensshUpgrade openssh-clientsUpgrade openssh-keycat-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-clients-debuginfoUpgrade openssh-serverUpgrade openssh-debuginfoUpgrade openssh-debugsourceUpgrade openssh-server-debuginfo | Feb 17, 2025 | Jul 8, 2024 |
| Arista Eos | — | Upgrade to a fixed EOS release or apply the available hotfix. As a temporary mitigation, enable SSH service ACLs or disable the SSH login grace time. | Jul 23, 2025 | Jul 8, 2024 |
| F5 Big Ip | — | — | Sep 9, 2024 | Jul 8, 2024 |
| Huawei Euleros 2_0_sp10 | — | Upgrade opensshUpgrade openssh-clientsUpgrade openssh-server | Mar 18, 2025 | Jul 8, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade openssh-clientsUpgrade openssh-serverUpgrade openssh | Oct 9, 2024 | Jul 8, 2024 |
| Huawei Euleros 2_0_sp9 | — | Upgrade openssh-serverUpgrade opensshUpgrade openssh-clients | Mar 18, 2025 | Jul 8, 2024 |
| Oracle_linux | — | Upgrade opensshUpgrade openssh-askpassUpgrade openssh-keycatUpgrade openssh-clientsUpgrade pam_ssh_agent_authUpgrade openssh-server | Aug 16, 2024 | Jul 8, 2024 |
| Redhat Openshift | — | Upgrade rhcos | Jul 25, 2024 | Jul 8, 2024 |
| Redhat_linux | — | Upgrade opensshUpgrade openssh-clients-debuginfoUpgrade openssh-askpassUpgrade openssh-sk-dummy-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-serverUpgrade openssh-keycat-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-debugsourceUpgrade openssh-askpass-debuginfoUpgrade openssh-debuginfoUpgrade pam_ssh_agent_authUpgrade openssh-clientsUpgrade openssh-keycat | Jul 16, 2024 | Jul 8, 2024 |
| Rocky_linux | — | Upgrade openssh-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-askpass-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-clientsUpgrade openssh-clients-debuginfoUpgrade openssh-serverUpgrade openssh-keycatUpgrade openssh-debugsourceUpgrade opensshUpgrade openssh-keycat-debuginfoUpgrade openssh-askpassUpgrade pam_ssh_agent_auth | Jul 16, 2024 | Jul 8, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub