7.0 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): HIGH
Openssh: possible remote code execution due to a race condition in signal handling affecting red hat enterprise linux 9
A signal handler race condition vulnerability was found in OpenSSH's server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog(). This issue leaves it vulnerable to a signal handler race condition on the cleanup_exit() function, which introduces the same vulnerability as CVE-2024-6387 in the unprivileged child of the SSHD server.
References
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- http://www.openwall.com/lists/oss-security/2024/07/09/5
- https://bugzilla.suse.com/show_bug.cgi?id=1227217
- https://www.suse.com/security/cve/CVE-2024-6409.html
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/
- http://www.openwall.com/lists/oss-security/2024/07/10/1
- http://www.openwall.com/lists/oss-security/2024/07/10/2
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91…
- https://bugzilla.suse.com/show_bug.cgi?id=1227217
- https://www.suse.com/security/cve/CVE-2024-6409.html
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/
- http://www.openwall.com/lists/oss-security/2024/07/10/1
- http://www.openwall.com/lists/oss-security/2024/07/10/2
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91…
- https://security.netapp.com/advisory/ntap-20240712-0003/
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- http://www.openwall.com/lists/oss-security/2024/07/09/5
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- http://www.openwall.com/lists/oss-security/2024/07/09/5
- http://www.openwall.com/lists/oss-security/2024/07/10/1
- http://www.openwall.com/lists/oss-security/2024/07/10/2
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://bugzilla.suse.com/show_bug.cgi?id=1227217
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91…
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://security.netapp.com/advisory/ntap-20240712-0003/
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- https://www.suse.com/security/cve/CVE-2024-6409.html
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://bugzilla.suse.com/show_bug.cgi?id=1227217
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91…
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://security.netapp.com/advisory/ntap-20240712-0003/
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- https://www.suse.com/security/cve/CVE-2024-6409.html
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- http://www.openwall.com/lists/oss-security/2024/07/09/5
- http://www.openwall.com/lists/oss-security/2024/07/10/1
- http://www.openwall.com/lists/oss-security/2024/07/10/2
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- http://www.openwall.com/lists/oss-security/2024/07/09/5
- http://www.openwall.com/lists/oss-security/2024/07/10/1
- http://www.openwall.com/lists/oss-security/2024/07/10/2
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://bugzilla.suse.com/show_bug.cgi?id=1227217
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91…
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://security.netapp.com/advisory/ntap-20240712-0003/
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- https://www.suse.com/security/cve/CVE-2024-6409.html
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- http://www.openwall.com/lists/oss-security/2024/07/09/5
- http://www.openwall.com/lists/oss-security/2024/07/10/1
- http://www.openwall.com/lists/oss-security/2024/07/10/2
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://bugzilla.suse.com/show_bug.cgi?id=1227217
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91…
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://security.netapp.com/advisory/ntap-20240712-0003/
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- https://www.suse.com/security/cve/CVE-2024-6409.html
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- http://www.openwall.com/lists/oss-security/2024/07/09/5
- http://www.openwall.com/lists/oss-security/2024/07/10/1
- http://www.openwall.com/lists/oss-security/2024/07/10/2
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://bugzilla.suse.com/show_bug.cgi?id=1227217
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91…
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://security.netapp.com/advisory/ntap-20240712-0003/
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- https://www.suse.com/security/cve/CVE-2024-6409.html
- http://www.openwall.com/lists/oss-security/2024/07/08/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/5 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/1 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/2 x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry x_transferred
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/ x_transferred
- RHBZ#2295085 issue-tracking x_refsource_REDHAT x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=1227217 x_transferred
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html x_transferred
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91… x_transferred
- https://security-tracker.debian.org/tracker/CVE-2024-6409 x_transferred
- https://security.netapp.com/advisory/ntap-20240712-0003/ x_transferred
- https://sig-security.rocky.page/issues/CVE-2024-6409/ x_transferred
- https://ubuntu.com/security/CVE-2024-6409 x_transferred
- https://www.suse.com/security/cve/CVE-2024-6409.html x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- http://www.openwall.com/lists/oss-security/2024/07/09/5
- http://www.openwall.com/lists/oss-security/2024/07/10/1
- http://www.openwall.com/lists/oss-security/2024/07/10/2
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4910 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://bugzilla.suse.com/show_bug.cgi?id=1227217
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91…
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://security.netapp.com/advisory/ntap-20240712-0003/
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- https://www.suse.com/security/cve/CVE-2024-6409.html
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/ x_transferred
- RHBZ#2295085 issue-tracking x_refsource_REDHAT x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=1227217 x_transferred
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html x_transferred
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91… x_transferred
- https://security-tracker.debian.org/tracker/CVE-2024-6409 x_transferred
- https://security.netapp.com/advisory/ntap-20240712-0003/ x_transferred
- https://sig-security.rocky.page/issues/CVE-2024-6409/ x_transferred
- https://ubuntu.com/security/CVE-2024-6409 x_transferred
- https://www.suse.com/security/cve/CVE-2024-6409.html x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/08/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/5 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/1 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/2 x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- http://www.openwall.com/lists/oss-security/2024/07/09/5
- http://www.openwall.com/lists/oss-security/2024/07/10/1
- http://www.openwall.com/lists/oss-security/2024/07/10/2
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4910 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4955 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4960 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://bugzilla.suse.com/show_bug.cgi?id=1227217
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91…
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://security.netapp.com/advisory/ntap-20240712-0003/
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- https://www.suse.com/security/cve/CVE-2024-6409.html
- http://www.openwall.com/lists/oss-security/2024/07/08/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/5 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/1 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/2 x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry x_transferred
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/ x_transferred
- RHBZ#2295085 issue-tracking x_refsource_REDHAT x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=1227217 x_transferred
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html x_transferred
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91… x_transferred
- https://security-tracker.debian.org/tracker/CVE-2024-6409 x_transferred
- https://security.netapp.com/advisory/ntap-20240712-0003/ x_transferred
- https://sig-security.rocky.page/issues/CVE-2024-6409/ x_transferred
- https://ubuntu.com/security/CVE-2024-6409 x_transferred
- https://www.suse.com/security/cve/CVE-2024-6409.html x_transferred
- RHSA-2024:4960 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://bugzilla.suse.com/show_bug.cgi?id=1227217
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91…
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://security.netapp.com/advisory/ntap-20240712-0003/
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- https://www.suse.com/security/cve/CVE-2024-6409.html
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- http://www.openwall.com/lists/oss-security/2024/07/09/5
- http://www.openwall.com/lists/oss-security/2024/07/10/1
- http://www.openwall.com/lists/oss-security/2024/07/10/2
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4910 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4955 x_refsource_REDHAT vendor-advisory
- http://www.openwall.com/lists/oss-security/2024/07/08/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/5 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/1 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/2 x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry x_transferred
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/ x_transferred
- RHBZ#2295085 issue-tracking x_refsource_REDHAT x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=1227217 x_transferred
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html x_transferred
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91… x_transferred
- https://security-tracker.debian.org/tracker/CVE-2024-6409 x_transferred
- https://security.netapp.com/advisory/ntap-20240712-0003/ x_transferred
- https://sig-security.rocky.page/issues/CVE-2024-6409/ x_transferred
- https://ubuntu.com/security/CVE-2024-6409 x_transferred
- https://www.suse.com/security/cve/CVE-2024-6409.html x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- http://www.openwall.com/lists/oss-security/2024/07/09/5
- http://www.openwall.com/lists/oss-security/2024/07/10/1
- http://www.openwall.com/lists/oss-security/2024/07/10/2
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4910 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4955 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4960 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://bugzilla.suse.com/show_bug.cgi?id=1227217
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91…
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://security.netapp.com/advisory/ntap-20240712-0003/
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- https://www.suse.com/security/cve/CVE-2024-6409.html
- http://www.openwall.com/lists/oss-security/2024/07/08/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/5 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/1 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/2 x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry x_transferred
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/ x_transferred
- RHBZ#2295085 issue-tracking x_refsource_REDHAT x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=1227217 x_transferred
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html x_transferred
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91… x_transferred
- https://security-tracker.debian.org/tracker/CVE-2024-6409 x_transferred
- https://security.netapp.com/advisory/ntap-20240712-0003/ x_transferred
- https://sig-security.rocky.page/issues/CVE-2024-6409/ x_transferred
- https://ubuntu.com/security/CVE-2024-6409 x_transferred
- https://www.suse.com/security/cve/CVE-2024-6409.html x_transferred
- RHSA-2024:4955 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4960 x_refsource_REDHAT vendor-advisory
- RHSA-2024:5444 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://bugzilla.suse.com/show_bug.cgi?id=1227217
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91…
- https://security-tracker.debian.org/tracker/CVE-2024-6409
- https://security.netapp.com/advisory/ntap-20240712-0003/
- https://sig-security.rocky.page/issues/CVE-2024-6409/
- https://ubuntu.com/security/CVE-2024-6409
- https://www.suse.com/security/cve/CVE-2024-6409.html
- http://www.openwall.com/lists/oss-security/2024/07/08/2
- http://www.openwall.com/lists/oss-security/2024/07/09/2
- http://www.openwall.com/lists/oss-security/2024/07/09/5
- http://www.openwall.com/lists/oss-security/2024/07/10/1
- http://www.openwall.com/lists/oss-security/2024/07/10/2
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4910 x_refsource_REDHAT vendor-advisory
- http://www.openwall.com/lists/oss-security/2024/07/08/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/5 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/1 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/2 x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry x_transferred
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/ x_transferred
- RHBZ#2295085 issue-tracking x_refsource_REDHAT x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=1227217 x_transferred
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html x_transferred
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91… x_transferred
- https://security-tracker.debian.org/tracker/CVE-2024-6409 x_transferred
- https://security.netapp.com/advisory/ntap-20240712-0003/ x_transferred
- https://sig-security.rocky.page/issues/CVE-2024-6409/ x_transferred
- https://ubuntu.com/security/CVE-2024-6409 x_transferred
- https://www.suse.com/security/cve/CVE-2024-6409.html x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4910 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4955 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4960 x_refsource_REDHAT vendor-advisory
- RHSA-2024:5444 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry x_transferred
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/ x_transferred
- RHBZ#2295085 issue-tracking x_refsource_REDHAT x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=1227217 x_transferred
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html x_transferred
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91… x_transferred
- https://security-tracker.debian.org/tracker/CVE-2024-6409 x_transferred
- https://security.netapp.com/advisory/ntap-20240712-0003/ x_transferred
- https://sig-security.rocky.page/issues/CVE-2024-6409/ x_transferred
- https://ubuntu.com/security/CVE-2024-6409 x_transferred
- https://www.suse.com/security/cve/CVE-2024-6409.html x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/08/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/5 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/1 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/2 x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4910 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4955 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4960 x_refsource_REDHAT vendor-advisory
- RHSA-2024:5444 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry x_transferred
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/ x_transferred
- RHBZ#2295085 issue-tracking x_refsource_REDHAT x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=1227217 x_transferred
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html x_transferred
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91… x_transferred
- https://security-tracker.debian.org/tracker/CVE-2024-6409 x_transferred
- https://security.netapp.com/advisory/ntap-20240712-0003/ x_transferred
- https://sig-security.rocky.page/issues/CVE-2024-6409/ x_transferred
- https://ubuntu.com/security/CVE-2024-6409 x_transferred
- https://www.suse.com/security/cve/CVE-2024-6409.html x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/08/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/5 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/1 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/2 x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4910 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4955 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4960 x_refsource_REDHAT vendor-advisory
- RHSA-2024:5444 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2024/07/08/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/5 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/1 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/2 x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry x_transferred
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/ x_transferred
- RHBZ#2295085 issue-tracking x_refsource_REDHAT x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=1227217 x_transferred
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html x_transferred
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91… x_transferred
- https://security-tracker.debian.org/tracker/CVE-2024-6409 x_transferred
- https://security.netapp.com/advisory/ntap-20240712-0003/ x_transferred
- https://sig-security.rocky.page/issues/CVE-2024-6409/ x_transferred
- https://ubuntu.com/security/CVE-2024-6409 x_transferred
- https://www.suse.com/security/cve/CVE-2024-6409.html x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4910 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4955 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4960 x_refsource_REDHAT vendor-advisory
- RHSA-2024:5444 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2024/07/08/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/5 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/1 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/2 x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry x_transferred
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/ x_transferred
- RHBZ#2295085 issue-tracking x_refsource_REDHAT x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=1227217 x_transferred
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html x_transferred
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91… x_transferred
- https://security-tracker.debian.org/tracker/CVE-2024-6409 x_transferred
- https://security.netapp.com/advisory/ntap-20240712-0003/ x_transferred
- https://sig-security.rocky.page/issues/CVE-2024-6409/ x_transferred
- https://ubuntu.com/security/CVE-2024-6409 x_transferred
- https://www.suse.com/security/cve/CVE-2024-6409.html x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4910 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4955 x_refsource_REDHAT vendor-advisory
- RHSA-2024:4960 x_refsource_REDHAT vendor-advisory
- RHSA-2024:5444 x_refsource_REDHAT vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry
- RHBZ#2295085 issue-tracking x_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2024/07/08/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/2 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/09/5 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/1 x_transferred
- http://www.openwall.com/lists/oss-security/2024/07/10/2 x_transferred
- RHSA-2024:4457 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4613 x_refsource_REDHAT vendor-advisory x_transferred
- RHSA-2024:4716 x_refsource_REDHAT vendor-advisory x_transferred
- https://access.redhat.com/security/cve/CVE-2024-6409 x_refsource_REDHAT vdb-entry x_transferred
- https://almalinux.org/blog/2024-07-09-cve-2024-6409/ x_transferred
- RHBZ#2295085 issue-tracking x_refsource_REDHAT x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=1227217 x_transferred
- https://explore.alas.aws.amazon.com/CVE-2024-6409.html x_transferred
- https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91… x_transferred
- https://security-tracker.debian.org/tracker/CVE-2024-6409 x_transferred
- https://security.netapp.com/advisory/ntap-20240712-0003/ x_transferred
- https://sig-security.rocky.page/issues/CVE-2024-6409/ x_transferred
- https://ubuntu.com/security/CVE-2024-6409 x_transferred
- https://www.suse.com/security/cve/CVE-2024-6409.html x_transferred
Affected products
- *
- *
Matching in nixpkgs
pkgs.opensshTest
Implementation of the SSH protocol
-
nixos-unstable -
- nixpkgs-unstable 10.0p2
pkgs.openssh_hpn
Implementation of the SSH protocol with high performance networking patches
-
nixos-unstable -
- nixpkgs-unstable 10.0p2
pkgs.openssh_gssapi
Implementation of the SSH protocol with GSSAPI support
-
nixos-unstable -
- nixpkgs-unstable 10.0p2
pkgs.opensshWithKerberos
Implementation of the SSH protocol
-
nixos-unstable -
- nixpkgs-unstable 10.0p2
pkgs.openssh_hpnWithKerberos
Implementation of the SSH protocol with high performance networking patches
-
nixos-unstable -
- nixpkgs-unstable 10.0p2
pkgs.lxqt.lxqt-openssh-askpass
GUI to query passwords on behalf of SSH agents
-
nixos-unstable -
- nixpkgs-unstable 2.2.0
Package maintainers
-
@romildo José Romildo Malaquias <malaquias@gmail.com>
-
@philiptaron Philip Taron <philip.taron@gmail.com>
-
@helsinki-Jo Joachim Ernst <joachim.ernst@helsinki-systems.de>
-
@dasJ Janne Heß <janne@hess.ooo>
-
@Conni2461 Simon Hauser <simon-hauser@outlook.com>
-
@numinit Morgan Jones <me+nixpkgs@numin.it>
-
@wahjava Ashish SHUKLA <ashish.is@lostca.se>