CVE-2024-6387
Description
Important: openssh security update
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-4312.html
Vendor advisory: alma — https://bugzilla.redhat.com/2294604
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-6387
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2024-6387.html
Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://news.ycombinator.com/item?id=40843778
Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://lists.mindrot.org/pipermail/openssh-unix-dev/2024-July/041431.html
Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-July/000158.html
Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://github.com/openela-main/openssh/commit/e1f438970e5a337a17070a637c1b9e19697cad09
Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — https://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2024-002.txt.asc
Vendor advisory: af854a3a-2127-422b-91ae-364da2661108 — http://www.openwall.com/lists/oss-security/2024/07/03/3
Vendor advisory: secalert@redhat.com — https://www.openssh.com/txt/release-9.8
Vendor advisory: arch — https://security.archlinux.org/ASA-202407-1
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:4312
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| arch | fixed | 9.8p1-1 | |
| sles | affected | | |
| debian | bookworm | fixed | 1:9.2p1-2+deb12u3 |
| debian | bullseye | fixed | 0 |
| debian | forky | fixed | 1:9.7p1-7 |
| debian | sid | fixed | 1:9.7p1-7 |
| debian | trixie | fixed | 1:9.7p1-7 |
| ubuntu | 23.10 | affected | |
| ubuntu | 24.04 | affected | |
| ubuntu | 22.04 | affected | |
| ubuntu | 22.10 | affected | |
| ubuntu | 23.04 | affected | |
| debian | 12.0 | affected | |
| rhel | 9.0 | affected | |
| rhel | 9.4 | affected | |
| rhel | 9.0_aarch64 | affected | |
| macos | affected | 12.7.6 | |
| freebsd | 13.2 | affected | |
| freebsd | 13.3 | affected | |
| freebsd | 14.0 | affected | |
| freebsd | 14.1 | affected | |
| freebsd | affected | | |
| almalinux | 9.0 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| openbsd | openssh | 8.6 | |
| openbsd | openssh | 4.4 | |
| openbsd | openssh | 8.5 | |
| openbsd | openssh | {"endExcluding":"4.4"} | 4.4 |
| redhat | openshift_container_platform | 4.0 | |
| netapp | active_iq_unified_manager | - | |
| netapp | e-series_santricity_os_controller | {"startIncluding":"11.0.0","endIncluding":"11.70.2"} | |
| netapp | ontap | 9 | |
| netapp | ontap_select_deploy_administration_utility | - | |
| netapp | ontap_tools | 9 | |
| netapp | ontap_tools | 10 | |
References
- https://access.redhat.com/errata/RHSA-2024:4312
- https://security.archlinux.org/ASA-202407-1
- https://access.redhat.com/errata/RHSA-2024:4340
- https://access.redhat.com/errata/RHSA-2024:4389
- https://access.redhat.com/errata/RHSA-2024:4469
- https://access.redhat.com/errata/RHSA-2024:4474
- https://access.redhat.com/errata/RHSA-2024:4479
- https://access.redhat.com/errata/RHSA-2024:4484
- https://access.redhat.com/security/cve/CVE-2024-6387
- https://bugzilla.redhat.com/show_bug.cgi?id=2294604
- https://santandersecurityresearch.github.io/blog/sshing_the_masses.html
- https://www.openssh.com/txt/release-9.8
- https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt
- http://seclists.org/fulldisclosure/2024/Jul/18
- http://seclists.org/fulldisclosure/2024/Jul/19
- http://seclists.org/fulldisclosure/2024/Jul/20
- http://www.openwall.com/lists/oss-security/2024/07/01/12
- http://www.openwall.com/lists/oss-security/2024/07/01/13
- http://www.openwall.com/lists/oss-security/2024/07/02/1
- http://www.openwall.com/lists/oss-security/2024/07/03/1
- http://www.openwall.com/lists/oss-security/2024/07/03/11
- http://www.openwall.com/lists/oss-security/2024/07/03/2
- http://www.openwall.com/lists/oss-security/2024/07/03/3
- http://www.openwall.com/lists/oss-security/2024/07/03/4
- http://www.openwall.com/lists/oss-security/2024/07/03/5
CWEs
CWE-364 CWE-362
Verify integrity in audit chain (admin only). AS-IS.