A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog(). As a consequence of a successful attack, in the worst case scenario, an attacker may be able to perform a remote code execution (RCE) as an unprivileged user running the sshd server.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssh-clientsUpgrade openssh-askpassUpgrade openssh-serverUpgrade opensshUpgrade openssh-keycatUpgrade pam_ssh_agent_auth | Jul 19, 2024 | Jul 8, 2024 |
| Amazon_linux_2023 | — | Upgrade opensshUpgrade pam_ssh_agent_authUpgrade openssh-keycatUpgrade openssh-keycat-debuginfoUpgrade openssh-clientsUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-serverUpgrade openssh-debugsourceUpgrade openssh-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-clients-debuginfo | Feb 17, 2025 | Jul 8, 2024 |
| Arista Eos | — | Upgrade to a fixed EOS release or apply the available hotfix. As a temporary mitigation, enable SSH service ACLs or disable the SSH login grace time. | Jul 23, 2025 | Jul 8, 2024 |
| F5 Big Ip | — | — | Sep 9, 2024 | Jul 8, 2024 |
| Huawei Euleros 2_0_sp10 | — | Upgrade opensshUpgrade openssh-clientsUpgrade openssh-server | Mar 18, 2025 | Jul 8, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade opensshUpgrade openssh-clientsUpgrade openssh-server | Oct 9, 2024 | Jul 8, 2024 |
| Huawei Euleros 2_0_sp9 | — | Upgrade opensshUpgrade openssh-serverUpgrade openssh-clients | Mar 18, 2025 | Jul 8, 2024 |
| Oracle_linux | — | Upgrade openssh-serverUpgrade openssh-keycatUpgrade pam_ssh_agent_authUpgrade opensshUpgrade openssh-askpassUpgrade openssh-clients | Aug 16, 2024 | Jul 8, 2024 |
| Redhat Openshift | — | Upgrade rhcos | Jul 25, 2024 | Jul 8, 2024 |
| Redhat_linux | — | Upgrade openssh-keycatUpgrade openssh-clientsUpgrade pam_ssh_agent_authUpgrade openssh-debuginfoUpgrade openssh-keycat-debuginfoUpgrade openssh-debugsourceUpgrade openssh-askpassUpgrade openssh-serverUpgrade openssh-sk-dummy-debuginfoUpgrade openssh-clients-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-askpass-debuginfoUpgrade opensshUpgrade pam_ssh_agent_auth-debuginfo | Jul 16, 2024 | Jul 8, 2024 |
| Rocky_linux | — | Upgrade pam_ssh_agent_authUpgrade openssh-debugsourceUpgrade opensshUpgrade openssh-askpassUpgrade openssh-keycat-debuginfoUpgrade openssh-keycatUpgrade openssh-clientsUpgrade openssh-askpass-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-serverUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-clients-debuginfoUpgrade openssh-debuginfo | Jul 16, 2024 | Jul 8, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub