Race condition in OpenSSH - CVE-2024-6387

 

Race condition in OpenSSH - CVE-2024-6387

Published: July 1, 2024 / Updated: February 28, 2025


Vulnerability identifier: #VU93513
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-6387
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in portable version of sshd. A remote non-authenticated attacker can send a series of requests in order to trigger a race condition and execute arbitrary code on the system.


Affected software

OpenSSH
FortiWeb
Oracle Communications Session Border Controller
Arch Linux
Amazon Linux AMI
Oracle Linux
Gentoo Linux
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
IBM AIX
IBM i
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
NetBSD
macOS
FreeBSD
Slackware Linux
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Junos OS
Junos OS Evolved
Fedora
Arista Extensible Operating System (EOS)
Aruba CX 9300 Switch Series
Aruba CX 8400 Switch Series
Aruba CX 8360 Switch Series
Aruba CX 8325 Switch Series
Aruba CX 8320 Switch Series
Aruba CX 6400 Switch Series
Aruba CX 6300 Switch Series
Aruba CX 6200F Switch Series
Aruba CX 6100 Switch Series
Aruba CX 6000 Switch Series
Aruba CX 4100i Switch Series
Aruba CX 10000 Switch Series
FortiExtender
FortiSwitch
FortiWLC
Arista Wireless Access Points
Red Hat OpenShift on IBM Cloud
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Data Virtualization (DV) on Cloud Pak for Data (CPD)
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Db2 Big SQL
HP-UX 11i Secure Shell
Cray EX235a
Dell Hybrid Client
Watson CP4D Data Stores
Aruba Fabric Composer
Storage Virtualize
IBM Virtualization Engine TS7700 3948-VED
NetScaler Console (formerly NetScaler ADM)
PRC7000
QuTS hero
SmartFabric Storage Software
LANTIME Operating System Firmware (LTOS)
Cray EX255a
Cray EX254n
Cray EX425
Cray EX420
Cray XD670
Superdome Flex 280 Server
QNAP QES
Aruba Instant On 1930 switches
Z9664F-ON
Superdome Flex Server
Virtualization Engine TS7700 3957-VED
PowerScale OneFS
ArubaOS-CX (AOS-CX)
QRadar Suite
FortiDDoS
FortiManager
FortiAnalyzer
FortiMail
FortiNAC-F
FortiAnalyzer-BigData
Arista NDR
FortiAIOps
FortiDDoS-F
FortiTester
FortiADC
Cray EX235n
Cray EX4252
Athonet Mobile Core
Athonet IMS
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Match 360
OpenShift Logging
IBM VIOS
Sun ZFS Storage Appliance Kit
Citrix NetScaler Gateway
FortiSandbox
QNAP QTS
IBM Storage Scale System
FortiDeceptor
FortiAuthenticator
FortiRecorder
FortiVoice
Voice Gateway
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
pam_ssh_agent_auth
openssh (Red Hat package)
openssh
openssh-keycat
openssh-debugsource
openssh-debuginfo
openssh-clients
openssh-askpass
openssh-server
openssh-help
openssh-client (Ubuntu package)
openssh-server (Ubuntu package)
openssh (Debian package)
openssh-doc
openssh-sk-dummy
openssh-server-debuginfo
openssh-common
openssh-cavs
openssh-clients-debuginfo
openssh-askpass-gnome-debugsource
openssh-askpass-gnome
openssh-helpers-debuginfo
openssh-server-config-disallow-rootlogin
openssh-helpers
openssh-fips
openssh-askpass-gnome-debuginfo
openssh-cavs-debuginfo
openssh-common-debuginfo
Z9432F-ON
S5448F-ON
Red Hat OpenShift Container Platform
Dell Virtual Storage Integrator for VMware vSphere Client
Citrix Netscaler ADC
iDRAC9
IBM Security Guardium

How to mitigate CVE-2024-6387

Install updates from vendor's website.

OpenSSH - update to 9.8p1
PRC7000 - addressed in versions 1.11.12.5, 1.11.13.2
SmartFabric Storage Software - update to 1.4.3
QRadar Suite - update to 1.10.25.0
FortiAIOps - update to 2.0.2
FortiSandbox - addressed in versions 4.0.6, 4.2.8, 4.4.7
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.0.1
FortiDeceptor - addressed in versions 5.2.1, 5.3.2
FortiDDoS - update to 5.7.4
FortiRecorder - addressed in versions 6.0.13, 6.4.6, 7.0.5, 7.2.2
FortiManager - addressed in versions 6.4.15, 7.0.13, 7.2.6, 7.4.4
FortiAnalyzer - addressed in versions 6.4.15, 7.0.13, 7.2.6, 7.4.4
FortiMail - addressed in versions 6.4.9, 7.0.8, 7.2.7, 7.4.3
FortiVoice - addressed in versions 6.4.10, 7.0.3
FortiAuthenticator - update to 6.6.2
FortiExtender - addressed in versions 7.0.6, 7.2.6, 7.4.6
FortiDDoS-F - update to 7.0.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.014
FortiWeb - addressed in versions 7.2.10, 7.4.5, 7.6.1
FortiNAC-F - addressed in versions 7.2.7, 7.4.1
FortiTester - addressed in versions 7.2.4, 7.3.3, 7.4.3
FortiSwitch - addressed in versions 7.2.9, 7.4.4
FortiADC - addressed in versions 7.2.7, 7.4.5
FortiAnalyzer-BigData - update to 7.4.1
FortiWLC - update to 8.6.8
macOS - addressed in versions 12.7.6 21H1320, 13.6.8 22G820, 14.6 23G80
Junos OS - addressed in versions 24.2R1-S2, 24.2R2, 24.4R1
Junos OS Evolved - addressed in versions 24.2R1-S2-EVO, 24.2R2-EVO, 24.4R1-EVO
HP-UX 11i Secure Shell - update to A.09.30.007
pam_ssh_agent_auth - addressed in versions 0.10.4-4.4, 0.10.4-4.31
Voice Gateway - update to 1.0.8.20
Cray EX235a - update to 1.9.5-39
Cray EX235n - update to 1.9.5-39
Cray EX255a - update to 1.9.5-39
Cray EX254n - update to 1.9.5-39
Cray EX4252 - update to 1.9.5-39
Cray EX425 - update to 1.9.5-39
Cray EX420 - update to 1.9.5-39
Cray XD670 - update to 1.19
Athonet Mobile Core - update to 1.24.1.1
Athonet IMS - update to 1.24.1.1
Superdome Flex 280 Server - update to 1.90.12
QNAP QES - update to 2.2.1 20250304
Dell Hybrid Client - addressed in versions 2.5 2310, 2403
Red Hat Advanced Cluster Management for Kubernetes - update to 2.10.4
Aruba Instant On 1930 switches - update to 3.0.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
Z9432F-ON - update to 3.51.5.1-21
S5448F-ON - update to 3.52.5.1-12
Z9664F-ON - update to 3.54.5.1-9
Superdome Flex Server - update to 4.0.10
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.61, 4.13.45, 4.14.33, 4.16.3
Arista Extensible Operating System (EOS) - update to 4.32.2F
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0.1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.1
Watson CP4D Data Stores - update to 5.0.2
IBM Match 360 - update to 5.0.3
Arista NDR - update to 5.2.3
OpenShift Logging - update to 5.8.9
IBM Storage Scale System - addressed in versions 6.1.9.4, 6.2.1.0
iDRAC9 - addressed in versions 7.00.00.173, 7.10.50.10
Aruba Fabric Composer - update to 7.0.3
openssh (Red Hat package) - update to 8.7p1-30.el9_2.4
Storage Virtualize - addressed in versions 8.7.0.3, 8.7.2.0
openssh - addressed in versions 8.8p1-31, 9.3p2-4
openssh-keycat - addressed in versions 8.8p1-31, 9.3p2-4
openssh-debugsource - addressed in versions 8.8p1-31, 9.3p2-4
openssh-debuginfo - addressed in versions 8.8p1-31, 9.3p2-4
openssh-clients - addressed in versions 8.8p1-31, 9.3p2-4
openssh-askpass - addressed in versions 8.8p1-31, 9.3p2-4
openssh-server - addressed in versions 8.8p1-31, 9.3p2-4
openssh-help - addressed in versions 8.8p1-31, 9.3p2-4
openssh-client (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.10, 1:9.3p1-1ubuntu3.6, 1:9.6p1-3ubuntu13.3
openssh-server (Ubuntu package) - addressed in versions 1:8.9p1-3ubuntu0.10, 1:9.3p1-1ubuntu3.6, 1:9.6p1-3ubuntu13.3
Virtualization Engine TS7700 3957-VED - addressed in versions 8.53.1.21 VTD_EXEC.279, 8.54.0.68 VTD_EXEC.279, 8.54.1.27 VTD_EXEC.279
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.53.1.21 VTD_EXEC.279, 8.54.0.68 VTD_EXEC.279, 8.54.1.27 VTD_EXEC.279
openssh (Debian package) - update to 1:9.2p1-2+deb12u3
openssh - addressed in versions 9.3p1-11.fc39, 9.6p1-1.fc40.4
openssh-clients - addressed in versions 9.3p2-2, 9.6p1-2
openssh - addressed in versions 9.3p2-2, 9.6p1-2
openssh-askpass - addressed in versions 9.3p2-2, 9.6p1-2
openssh-doc - addressed in versions 9.3p2-2, 9.6p1-2
openssh-sk-dummy - addressed in versions 9.3p2-2, 9.6p1-2
openssh-server - addressed in versions 9.3p2-2, 9.6p1-2
openssh-keycat - addressed in versions 9.3p2-2, 9.6p1-2
PowerScale OneFS - addressed in versions 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0
openssh-server-debuginfo - update to 9.6p1-150600.6.3.1
openssh-server - update to 9.6p1-150600.6.3.1
openssh-common - update to 9.6p1-150600.6.3.1
openssh-cavs - update to 9.6p1-150600.6.3.1
openssh-clients-debuginfo - update to 9.6p1-150600.6.3.1
openssh-askpass-gnome-debugsource - update to 9.6p1-150600.6.3.1
openssh-askpass-gnome - update to 9.6p1-150600.6.3.1
openssh-helpers-debuginfo - update to 9.6p1-150600.6.3.1
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.3.1
openssh-clients - update to 9.6p1-150600.6.3.1
openssh-helpers - update to 9.6p1-150600.6.3.1
openssh - update to 9.6p1-150600.6.3.1
openssh-debuginfo - update to 9.6p1-150600.6.3.1
openssh-fips - update to 9.6p1-150600.6.3.1
openssh-debugsource - update to 9.6p1-150600.6.3.1
openssh-askpass-gnome-debuginfo - update to 9.6p1-150600.6.3.1
openssh-cavs-debuginfo - update to 9.6p1-150600.6.3.1
openssh-common-debuginfo - update to 9.6p1-150600.6.3.1
openssh - update to 9.8p1-1
openssh - update to 9.8p1
Dell Virtual Storage Integrator for VMware vSphere Client - update to 10.7
ArubaOS-CX (AOS-CX) - addressed in versions 10.10.1131, 10.13.1031, 10.14.0007
IBM Security Guardium - addressed in versions 12.0p15, 12.0p30
Citrix Netscaler ADC - addressed in versions 12.1-55.309, 13.0-92.31, 13.1-37.190, 13.1-53.24, 14.1-25.56
NetScaler Console (formerly NetScaler ADM) - addressed in versions 13.0-92.31, 13.1-53.24, 14.1-25.56
Citrix NetScaler Gateway - update to 14.1-25.56
Arista Wireless Access Points - addressed in versions 16.1.0-51.1004, 17.0.0-241

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins