Information disclosure in OpenSSH - CVE-2024-39894
Published: July 1, 2024 / Updated: January 8, 2025
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due a logic error in ObscureKeystrokeTiming implementation within the ssh client. A local user with ability to passively observe SSH sessions can recover sensitive input, such as password for the su or sudo programs.
Affected software
Oracle Solaris
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
IBM i
FreeBSD
Desktop Applications Module
Basesystem Module
openSUSE Leap
Anolis OS
Junos OS
Junos OS Evolved
Ubuntu
macOS
LANTIME Operating System Firmware (LTOS)
openssh-server (Ubuntu package)
openssh-client (Ubuntu package)
openssh-doc
openssh-sk-dummy
openssh-server
openssh-keycat
openssh-clients
openssh-askpass
openssh
openssh-fips
openssh-debuginfo
openssh-helpers
openssh-clients-debuginfo
openssh-debugsource
openssh-server-config-disallow-rootlogin
openssh-cavs-debuginfo
openssh-server-debuginfo
openssh-askpass-gnome-debuginfo
openssh-helpers-debuginfo
openssh-cavs
openssh-common-debuginfo
openssh-common
openssh-askpass-gnome-debugsource
openssh-askpass-gnome
How to mitigate CVE-2024-39894
Oracle Solaris - update to 11.4 SRU 71
LANTIME Operating System Firmware (LTOS) - update to 7.08.014
Junos OS - addressed in versions 24.2R1-S2, 24.2R2, 24.4R1
Junos OS Evolved - addressed in versions 24.2R1-S2-EVO, 24.2R2-EVO, 24.4R1-EVO
openssh-server (Ubuntu package) - update to 1:9.6p1-3ubuntu13.4
openssh-client (Ubuntu package) - update to 1:9.6p1-3ubuntu13.4
openssh-doc - update to 9.6p1-3
openssh-sk-dummy - update to 9.6p1-3
openssh-server - update to 9.6p1-3
openssh-keycat - update to 9.6p1-3
openssh-clients - update to 9.6p1-3
openssh-askpass - update to 9.6p1-3
openssh - update to 9.6p1-3
openssh-clients - update to 9.6p1-150600.6.6.1
openssh-fips - update to 9.6p1-150600.6.6.1
openssh-debuginfo - update to 9.6p1-150600.6.6.1
openssh - update to 9.6p1-150600.6.6.1
openssh-helpers - update to 9.6p1-150600.6.6.1
openssh-clients-debuginfo - update to 9.6p1-150600.6.6.1
openssh-debugsource - update to 9.6p1-150600.6.6.1
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.6.1
openssh-cavs-debuginfo - update to 9.6p1-150600.6.6.1
openssh-server-debuginfo - update to 9.6p1-150600.6.6.1
openssh-askpass-gnome-debuginfo - update to 9.6p1-150600.6.6.1
openssh-helpers-debuginfo - update to 9.6p1-150600.6.6.1
openssh-server - update to 9.6p1-150600.6.6.1
openssh-cavs - update to 9.6p1-150600.6.6.1
openssh-common-debuginfo - update to 9.6p1-150600.6.6.1
openssh-common - update to 9.6p1-150600.6.6.1
openssh-askpass-gnome-debugsource - update to 9.6p1-150600.6.6.1
openssh-askpass-gnome - update to 9.6p1-150600.6.6.1
macOS - update to 15.0 24A335
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSH
- Ubuntu update for openssh
- SUSE update for openssh
- Oracle Solaris update for thrid-party components
- Multiple vulnerabilities in macOS Sequoia
- Junos OS and Junos OS Evolved update for OpenSSH
- Multiple vulnerabilities in Meinberg LANTIME firmware (July 2024)
- Multiple vulnerabilities in IBM i
- Anolis OS update for openssh
- OpenSSH Keystroke Obfuscation Bypass in FreeBSD