Codereliant’s Substack

Codereliant’s Substack

Share this post

Codereliant’s Substack
Codereliant’s Substack
Critical "RegreSSHion" discovered
Copy link
Facebook
Email
Notes
More

Critical "RegreSSHion" discovered

Team CodeReliant
Jul 04, 2024

Share this post

Codereliant’s Substack
Codereliant’s Substack
Critical "RegreSSHion" discovered
Copy link
Facebook
Email
Notes
More
Share
Photo by Marcel Eberle / Unsplash

Honey wake up, the new SSH vulnerability just dropped.

A new high-severity vulnerability in OpenSSH, dubbed "regreSSHion" (CVE-2024-6387), has been discovered couple days ago. This flaw affects OpenSSH servers on glibc-based Linux systems and could allow unauthenticated remote code execution with root privileges.

What you need to know:

  • The vulnerability impacts OpenSSH versions 8.5p1 to 9.7p1, as well as versions earlier than 4.4p1 (if not patched for older CVEs).

  • Over 14 million potentially vulnerable instances are exposed to the internet.

  • While there's no known exploitation in the wild yet, a working exploit has been developed by researchers. The complexity of the exploit might delay widespread attacks, but it's important to act quickly.

Action items:

  1. Update all OpenSSH instances to version 9.8p1 or later ASAP.

  2. If immediate patching isn't possible, set LoginGraceTime to 0 in the sshd config file as a temporary mitigation.

  3. Reduce the number of internet-facing sshd servers where possible to be less prone to Zero-day issues like this one.

If you want to know more you can check out the deep dive by Qualys Threat Research Unit, who discovered and reported the issue. Stay secure!

In our security analysis, we identified that this vulnerability is a regression of the previously patched vulnerability CVE-2006-5051, which was reported in 2006. A regression in this context means that a flaw, once fixed, has reappeared in a subsequent software release, typically due to changes or updates that inadvertently reintroduce the issue.


Join our newsletter for weekly tips and news

Share this post

Codereliant’s Substack
Codereliant’s Substack
Critical "RegreSSHion" discovered
Copy link
Facebook
Email
Notes
More
Share

Discussion about this post

User's avatar
Debug Golang Memory Leaks with Pprof
Managing memory effectively is important for the performance of any application.
Jul 12, 2023 • 
Team CodeReliant

Share this post

Codereliant’s Substack
Codereliant’s Substack
Debug Golang Memory Leaks with Pprof
Copy link
Facebook
Email
Notes
More
Hands-on Kubernetes Operator Development: Reconcile loop
Introduction & Environment Bootstrap
Jul 18, 2023 • 
Team CodeReliant
2

Share this post

Codereliant’s Substack
Codereliant’s Substack
Hands-on Kubernetes Operator Development: Reconcile loop
Copy link
Facebook
Email
Notes
More
Battle of the Frameworks: Benchmarking High-Performance HTTP Libraries
Have you ever wondered about how high performance HTTP servers will do across different languages?
Oct 23, 2023 • 
Team CodeReliant

Share this post

Codereliant’s Substack
Codereliant’s Substack
Battle of the Frameworks: Benchmarking High-Performance HTTP Libraries
Copy link
Facebook
Email
Notes
More

Ready for more?

© 2025 Codereliant
Privacy ∙ Terms ∙ Collection notice
Start writingGet the app
Substack is the home for great culture

Share

Copy link
Facebook
Email
Notes
More

Create your profile

User's avatar

Only paid subscribers can comment on this post

Already a paid subscriber? Sign in

Check your email

For your security, we need to re-authenticate you.

Click the link we sent to , or click here to sign in.